CNCF / Specialist / CKS
Certified Kubernetes Security Specialist
Reduce Kubernetes attack paths from cluster setup through software supply chains and runtime response.
Prior CKA pass required. Scope: CNCF v1.34 curriculum; Linux Foundation's candidate FAQ lists Kubernetes v1.35 on 10 October 2026. Verify the booked environment. This is one of the five Kubestronaut certifications. CNCF curriculum attribution: CC BY 4.0.
THE REVISION PATH
Your topics, in order.
Read. Recall. Explain the alternative.
Services, DNS and Network Policy
Selector finds endpoints; policy permits the path.
Cluster Lifecycle, RBAC and Extensions
API decides; controllers reconcile; nodes execute.
Cluster Exposure, Benchmarks and Trust
Close unnecessary paths before trusting the workload.
Host, Kernel and Container Hardening
Remove privileges, reduce syscalls, constrain filesystem access.
Pod Security, Secrets and Workload Encryption
Admission constrains configuration; identity constrains access.
Images, SBOMs and Admission Evidence
Know the contents, verify the origin, enforce before execution.
Audit Logs, Runtime Signals and Response
Observe the action, identify the actor, preserve the evidence.
How this guide is organised
Original revision notes arranged around practical decisions. The linked official objectives define the mapped scope; primary documentation supports the explanations. Read each topic, answer without looking, then explain why another option would fail.
- Official exam guide ↗ Scope authority
Revision material supports preparation; it does not guarantee every possible exam question. Check the exam version and official objectives before booking.