Certified Kubernetes Security Specialist (CKS) (CKS) Exam Blueprint

CKS

120 minDuration
67%Passing Score
$395Price
2 yearsValid For
1Languages
Practice Certified Kubernetes Security Specialist (CKS) on QuizForge

Credential type: certification examination · verified on the issuer's site September 18, 2026 issuer page

Exam Domains

Cluster Setup Cluster Setup 15%
  • 1.0Use Network security policies to restrict cluster level access
  • 1.1Use CIS benchmark to review the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
  • 1.2Properly set up Ingress with TLS
  • 1.3Protect node metadata and endpoints
  • 1.4Verify platform binaries before deploying
Cluster Hardening Cluster Hardening 15%
  • 2.0Use Role Based Access Controls to minimize exposure
  • 2.1Exercise caution in using service accounts e.g. disable defaults, minimize permissions on newly created ones
  • 2.2Restrict access to Kubernetes API
  • 2.3Upgrade Kubernetes to avoid vulnerabilities
System Hardening System Hardening 10%
  • 3.0Minimize host OS footprint (reduce attack surface)
  • 3.1Using least-privilege identity and access management
  • 3.2Minimize external access to the network
  • 3.3Appropriately use kernel hardening tools such as AppArmor, seccomp
Minimize Microservice Vulnerabilities Minimize Microservice Vulnerabilities 20%
  • 4.0Use appropriate pod security standards
  • 4.1Manage Kubernetes secrets
  • 4.2Understand and implement isolation techniques (multi-tenancy, sandboxed containers, etc.)
  • 4.3Implement Pod-to-Pod encryption (Cilium, Istio)
Supply Chain Security Supply Chain Security 20%
  • 5.0Minimize base image footprint
  • 5.1Understand your supply chain (e.g. SBOM, CI/CD, artifact repositories)
  • 5.2Secure your supply chain (permitted registries, sign and validate artifacts, etc.)
  • 5.3Perform static analysis of user workloads and container images (e.g. Kubesec, KubeLinter)
Monitoring, Logging and Runtime Security Monitoring, Logging and Runtime Security 20%
  • 6.0Perform behavioral analytics to detect malicious activities
  • 6.1Detect threats within physical infrastructure, apps, networks, data, users and workloads
  • 6.2Investigate and identify phases of attack and bad actors within the environment
  • 6.3Ensure immutability of containers at runtime
  • 6.4Use Kubernetes audit logs to monitor access

Exam Details

Question Typesperformance_based
FormatPerformance-based (hands-on terminal)
Online ProctoringAvailable
ID RequirementsGovernment-issued photo ID required. ID must match the name on the exam registration. Acceptable forms include passport, driver's license, or national ID card.
RenewalRequired -- Certifications are valid for 2 years. Renewal requires retaking and passing the exam before expiry. No CE credit option — exam retake is the only renewal path.
PrerequisitesActive CKA certification required (recommended)
Retake PolicyOne free retake attempt is included with the exam purchase. A minimum 12-hour waiting period is required between attempts. The free retake must be used within 12 months of the original purchase.
LanguagesEnglish

Official Study Resources