CKS: Kubernetes security in production
Prepare for CKS through Kubernetes security, images, auditing, and production-incident decisions.
Objectives and progression
Eight lessons, 50 questions, and eight original cases across six CKS domains. The internal assessment contains 32 decisions in 50 minutes. Fictional banking examples connect security configuration to continuity, RUN handover, suppliers, and incident response. The official exam is practical and command-line based; this decision preparation does not execute a cluster or replace authorized practice. Official sources state Kubernetes version 1.35; the exact curriculum edition date was not confirmed.
Audience: Kubernetes administrators, APS/L3 teams, security engineers, and technical platform managers.
Prerequisites: Experience with Linux, Kubernetes, RBAC, and troubleshooting. Taking CKS requires having taken and passed CKA according to the official source; the DR path does not grant eligibility.
274 estimated study minutes
- Distinguish allowed connectivity, authentication, and encryption.
- Analyze direct permissions and the effects of creating workloads.
- Connect syscalls, local profiles, and node preparation.
- Read admission rejection and correct the complete template.
- Treat credentials from delivery through retained backups.
- Bind approval to exact content and matching evidence.
- Collect what is needed without creating new data exposure.
- Turn an alert into containment, diagnosis, and verifiable recovery.
Modules
- Network boundaries and cluster exposure
- API identities and authorization
- Linux hardening and kernel controls
- Admission and workload protection
- Secrets, encryption, and recovery
- Artifacts, provenance, and vulnerabilities
- Auditing and evidence preservation
- Runtime detection and coordinated response
Continue learning
- CKA — Certified Kubernetes Administrator
- CKAD — Certified Kubernetes Application Developer
- KCNA — Kubernetes and Cloud Native Associate
- CompTIA Security+
- Linux Administration
References and version
Kubernetes v1.35; current six-domain CKS outline
- CKS certification and current domains · 2026-09-29
- CKA CKAD CKS FAQ · 2026-09-29
- CNCF CKS · 2026-09-29
- Ingress TLS · 2026-09-29
- Upgrade a cluster · 2026-09-29
- RuntimeClass · 2026-09-29
- KubeLinter project · 2026-09-29
- Security checklist · 2026-09-29
- Network policies · 2026-09-29
- Service accounts · 2026-09-29
- RBAC authorization · 2026-09-29
- RBAC good practices · 2026-09-29
- Linux kernel security constraints · 2026-09-29
- Security context · 2026-09-29
- Pod Security Standards · 2026-09-29
- Pod Security Admission · 2026-09-29
- Secret management · 2026-09-29
- Encryption at rest · 2026-09-29
- API auditing · 2026-09-29
- Verify signed Kubernetes artifacts · 2026-09-29
- Cosign verification · 2026-09-29
- Building best practices · 2026-09-29
- SBOM generation and scanning · 2026-09-29
- Falco runtime detection · 2026-09-29
- Mutual TLS migration · 2026-09-29
What you will explore
0 / 8Network boundaries and cluster exposure
Distinguish allowed connectivity, authentication, and encryption.
API identities and authorization
Analyze direct permissions and the effects of creating workloads.
Linux hardening and kernel controls
Connect syscalls, local profiles, and node preparation.
Admission and workload protection
Read admission rejection and correct the complete template.
Secrets, encryption, and recovery
Treat credentials from delivery through retained backups.
Artifacts, provenance, and vulnerabilities
Bind approval to exact content and matching evidence.
Auditing and evidence preservation
Collect what is needed without creating new data exposure.
Runtime detection and coordinated response
Turn an alert into containment, diagnosis, and verifiable recovery.