certslothcertsloth
← KCSA overview

Kubernetes and Cloud Security Associate / STUDY TOOLS

Exam coverage map

Reviewed 10 October 2026 against the current unversioned curriculum. The Linux Foundation scope explicitly includes authorization, which is omitted from the PDF bullet list; this guide covers both. CNCF also uses the expanded name Kubernetes and Cloud Native Security Associate. Curriculum attribution: CNCF, CC BY 4.0; explanations and questions are original. Check candidate instructions for current exam policies. Objective IDs are local navigation labels, not official codes.

Published objectives

Objective Revision topic
1.1 · Cloud, cluster, container and code layers 01 Security Layers and Shared Responsibility
1.2 · Provider and infrastructure responsibilities 01 Security Layers and Shared Responsibility
1.3 · Preventive, detective and corrective controls 01 Security Layers and Shared Responsibility, 09 Compliance, Frameworks and Automated Evidence
1.4 · Isolation mechanisms and their limits 01 Security Layers and Shared Responsibility, 04 Node, Runtime, Pod and Storage Boundaries, 06 Pod Standards, Admission and Network Segmentation
1.5 · Repository and container artifact assurance 02 Images, Registries and the Software Supply Chain
1.6 · Application and workload protection 01 Security Layers and Shared Responsibility, 02 Images, Registries and the Software Supply Chain
2.1 · API access and request processing 03 Control Plane, Etcd and Client Trust, 05 Identity, RBAC, Secrets and Audit Evidence
2.2 · Controller identities and reconciliation 03 Control Plane, Etcd and Client Trust
2.3 · Scheduler configuration and access 03 Control Plane, Etcd and Client Trust
2.4 · Kubelet endpoint protection 04 Node, Runtime, Pod and Storage Boundaries
2.5 · Runtime and host attack surface 04 Node, Runtime, Pod and Storage Boundaries
2.6 · Service proxy trust and exposure 04 Node, Runtime, Pod and Storage Boundaries
2.7 · Pod boundaries and host access 04 Node, Runtime, Pod and Storage Boundaries, 06 Pod Standards, Admission and Network Segmentation
2.8 · Etcd access, encryption and backups 03 Control Plane, Etcd and Client Trust
2.9 · Container network implementation 04 Node, Runtime, Pod and Storage Boundaries, 06 Pod Standards, Admission and Network Segmentation
2.10 · Client credentials and kubeconfig trust 03 Control Plane, Etcd and Client Trust
2.11 · Persistent data and storage permissions 04 Node, Runtime, Pod and Storage Boundaries
3.1 · Pod security levels 06 Pod Standards, Admission and Network Segmentation
3.2 · Pod security admission modes 06 Pod Standards, Admission and Network Segmentation
3.3 · Identity verification 05 Identity, RBAC, Secrets and Audit Evidence
3.4 · Permission grants and RBAC scope 05 Identity, RBAC, Secrets and Audit Evidence
3.5 · Secret handling and encryption 05 Identity, RBAC, Secrets and Audit Evidence
3.6 · Tenant and workload segmentation 06 Pod Standards, Admission and Network Segmentation
3.7 · API audit evidence 05 Identity, RBAC, Secrets and Audit Evidence
3.8 · Directional network access rules 06 Pod Standards, Admission and Network Segmentation
4.1 · Trust boundaries and information movement 07 Threat Modeling and Attack Paths
4.2 · Attacker persistence paths 07 Threat Modeling and Attack Paths
4.3 · Resource exhaustion and availability attacks 07 Threat Modeling and Attack Paths
4.4 · Compromised code and container execution 07 Threat Modeling and Attack Paths
4.5 · Network interception and lateral movement 07 Threat Modeling and Attack Paths
4.6 · Sensitive information exposure 07 Threat Modeling and Attack Paths
4.7 · Escalation from workload to platform privileges 07 Threat Modeling and Attack Paths
5.1 · Build integrity and artifact provenance 02 Images, Registries and the Software Supply Chain
5.2 · Registry trust and repository access 02 Images, Registries and the Software Supply Chain
5.3 · Metrics, logs, traces and runtime signals 08 Observability, PKI and Secure Connectivity
5.4 · Mesh workload identity and traffic policy 08 Observability, PKI and Secure Connectivity
5.5 · Certificate chains and key protection 08 Observability, PKI and Secure Connectivity
5.6 · Private connectivity, ingress and egress 08 Observability, PKI and Secure Connectivity
5.7 · Mutation, validation and policy enforcement 06 Pod Standards, Admission and Network Segmentation
6.1 · Organizational standards and configuration baselines 09 Compliance, Frameworks and Automated Evidence
6.2 · Structured threat analysis 07 Threat Modeling and Attack Paths, 09 Compliance, Frameworks and Automated Evidence
6.3 · Dependency evidence and release governance 02 Images, Registries and the Software Supply Chain, 09 Compliance, Frameworks and Automated Evidence
6.4 · Repeatable checks and policy automation 09 Compliance, Frameworks and Automated Evidence

Search across every published topic.