Skip to main content
← All posts·
Certifications

CKS Exam Preparation Guide 2026: Certified Kubernetes Security Specialist

CKS exam preparation guide for 2026. Covers cluster setup hardening, system hardening, minimise microservice vulnerabilities, supply chain security, monitoring and runtime security. Advanced security certification for Kubernetes professionals.

Luca Berton13 min read

CKS: The Security Certification Enterprise Kubernetes Needs

The Certified Kubernetes Security Specialist (CKS) is the hardest of the three Kubernetes certifications — and the most valuable for enterprise environments. In regulated industries where DORA, NIS2, and ISO 27001 require demonstrable security competence, CKS validates that your team can actually secure Kubernetes, not just run it.

Prerequisite: You must hold a valid CKA certification to take CKS.

Exam Format

  • Duration: 2 hours
  • Format: Performance-based (hands-on in real clusters)
  • Passing score: 67%
  • Prerequisite: Valid CKA certification
  • Cost: $395 USD (includes one retake)
  • Validity: 2 years

CKS Curriculum Domains

10% — Cluster Setup

  • Use network security policies to restrict cluster-level access
  • Use CIS benchmark to review the security configuration of Kubernetes components
  • Properly set up Ingress with TLS
  • Protect node metadata and endpoints
  • Minimise use of, and access to, GUI elements
  • Verify platform binaries before deploying

15% — Cluster Hardening

  • Restrict access to Kubernetes API
  • Use RBAC to minimise exposure
  • Exercise caution in using service accounts
  • Restrict access to Kubernetes Dashboard

15% — System Hardening

  • Minimise host OS footprint (reduce attack surface)
  • Minimise IAM roles
  • Minimise external access to the network
  • Appropriately use kernel hardening tools (AppArmor, seccomp)

20% — Minimise Microservice Vulnerabilities

  • Setup appropriate OS-level security domains (PSA/PSS, OPA, security contexts)
  • Manage Kubernetes secrets
  • Use container runtime sandboxes (gVisor, Kata)
  • Implement pod-to-pod encryption (mTLS via service mesh)

20% — Supply Chain Security

  • Minimise base image footprint
  • Secure your supply chain (allowlist registries, sign images, validate signatures)
  • Use static analysis of user workloads (kubesec, conftest)
  • Scan images for known vulnerabilities (Trivy, Grype)

20% — Monitoring, Logging and Runtime Security

  • Perform behavioural analytics of syscall process at host and container level (Falco)
  • Detect threats within physical infrastructure, apps, networks, data, users, and workloads
  • Investigate and identify phases of attack, and bad actors within the environment
  • Ensure immutability of containers at runtime
  • Use audit logs to monitor access
📘 Book

Kubernetes Recipes

A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).

Watch on Skillshare →

8-Week Study Plan

  • Weeks 1-2: Cluster setup + hardening. CIS benchmarks, RBAC deep dive, network policies.
  • Weeks 3-4: System hardening + microservice vulnerabilities. AppArmor, seccomp, PSA/PSS, OPA Gatekeeper.
  • Weeks 5-6: Supply chain security. Image scanning, signing, admission webhooks, registry security.
  • Weeks 7-8: Runtime security (Falco), audit logging, practice exams.

CKS for Regulated Enterprises

CKS-certified engineers are increasingly required for:

  • DORA compliance — TLPT testing of Kubernetes infrastructure requires deep security knowledge
  • NIS2 — Supply chain security and runtime monitoring map directly to NIS2 Art. 21 requirements
  • ISO 27001 — Annex A controls for container security require CKS-level expertise
  • SOC 2 — Runtime security monitoring and audit logging are key SOC 2 evidence
🎓 Course with Starweaver

Microsoft SQL Server Performance Tuning

Performance tuning essentials for SQL Server. In collaboration with Starweaver.

Start on Coursera →
CKS
Kubernetes
security
certification
exam preparation
study guide
CNCF

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

Or see AI readiness assessment scope & pricing

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →