CKS: The Security Certification Enterprise Kubernetes Needs
The Certified Kubernetes Security Specialist (CKS) is the hardest of the three Kubernetes certifications — and the most valuable for enterprise environments. In regulated industries where DORA, NIS2, and ISO 27001 require demonstrable security competence, CKS validates that your team can actually secure Kubernetes, not just run it.
Prerequisite: You must hold a valid CKA certification to take CKS.
Exam Format
- Duration: 2 hours
- Format: Performance-based (hands-on in real clusters)
- Passing score: 67%
- Prerequisite: Valid CKA certification
- Cost: $395 USD (includes one retake)
- Validity: 2 years
CKS Curriculum Domains
10% — Cluster Setup
- Use network security policies to restrict cluster-level access
- Use CIS benchmark to review the security configuration of Kubernetes components
- Properly set up Ingress with TLS
- Protect node metadata and endpoints
- Minimise use of, and access to, GUI elements
- Verify platform binaries before deploying
15% — Cluster Hardening
- Restrict access to Kubernetes API
- Use RBAC to minimise exposure
- Exercise caution in using service accounts
- Restrict access to Kubernetes Dashboard
15% — System Hardening
- Minimise host OS footprint (reduce attack surface)
- Minimise IAM roles
- Minimise external access to the network
- Appropriately use kernel hardening tools (AppArmor, seccomp)
20% — Minimise Microservice Vulnerabilities
- Setup appropriate OS-level security domains (PSA/PSS, OPA, security contexts)
- Manage Kubernetes secrets
- Use container runtime sandboxes (gVisor, Kata)
- Implement pod-to-pod encryption (mTLS via service mesh)
20% — Supply Chain Security
- Minimise base image footprint
- Secure your supply chain (allowlist registries, sign images, validate signatures)
- Use static analysis of user workloads (kubesec, conftest)
- Scan images for known vulnerabilities (Trivy, Grype)
20% — Monitoring, Logging and Runtime Security
- Perform behavioural analytics of syscall process at host and container level (Falco)
- Detect threats within physical infrastructure, apps, networks, data, users, and workloads
- Investigate and identify phases of attack, and bad actors within the environment
- Ensure immutability of containers at runtime
- Use audit logs to monitor access
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →8-Week Study Plan
- Weeks 1-2: Cluster setup + hardening. CIS benchmarks, RBAC deep dive, network policies.
- Weeks 3-4: System hardening + microservice vulnerabilities. AppArmor, seccomp, PSA/PSS, OPA Gatekeeper.
- Weeks 5-6: Supply chain security. Image scanning, signing, admission webhooks, registry security.
- Weeks 7-8: Runtime security (Falco), audit logging, practice exams.
CKS for Regulated Enterprises
CKS-certified engineers are increasingly required for:
- DORA compliance — TLPT testing of Kubernetes infrastructure requires deep security knowledge
- NIS2 — Supply chain security and runtime monitoring map directly to NIS2 Art. 21 requirements
- ISO 27001 — Annex A controls for container security require CKS-level expertise
- SOC 2 — Runtime security monitoring and audit logging are key SOC 2 evidence
Microsoft SQL Server Performance Tuning
Performance tuning essentials for SQL Server. In collaboration with Starweaver.
Start on Coursera →
Luca Berton
