Certified Kubernetes Security Specialist (CKS)
The CKS is an advanced, hands-on exam that requires a current CKA. It covers cluster setup and hardening (CIS benchmarks, NetworkPolicies, API server flags), system hardening (kernel, AppArmor, seccomp), minimizing microservice vulnerabilities (mTLS, admission controllers, RuntimeClasses), supply-chain security (image scanning, SBOM, signing), and runtime security and auditing with Falco and audit logs.
Ready to sit the mock exam?
The timer starts as soon as you begin. You can flag questions, move freely between them, and review everything before submitting. No sign-in required — sign in afterwards to save the result to your history.
Start CKS examSkills measured
Cluster Setup
15%NetworkPolicies, CIS benchmark checks with kube-bench, Ingress TLS, protecting node metadata, and securing GUI elements.
Cluster Hardening
15%Restricting API access, RBAC minimization, ServiceAccount hardening, and keeping Kubernetes updated.
System Hardening
10%Minimizing the host OS footprint, IAM roles, kernel hardening (AppArmor, seccomp), and reducing attack surface.
Minimize Microservice Vulnerabilities
20%SecurityContexts and Pod Security Standards, OPA/Gatekeeper and admission control, secrets management, mTLS, and sandboxed runtimes.
Supply Chain Security
20%Minimizing base-image footprint, image allowlisting, static analysis of workloads, and scanning images for known vulnerabilities.
Monitoring, Logging and Runtime Security
20%Behavioral analytics with Falco, detecting threats, immutable containers at runtime, and Kubernetes audit logging.