This guide covers all official objectives for the CKS exam, focusing on cluster setup, supply chain security, hardening, system hardening, microservice vulnerabilities, and runtime monitoring.
This guide works best as a loop: read a chapter, test yourself with practice questions, look up unfamiliar terms in the glossary, then move to the next chapter.
15 chapters covering every exam objective. Each chapter includes key concepts, exam tips, common traps, comparison tables, and a 5-question quiz at the end.
Start Chapter 1Free timed and untimed practice with instant feedback and full explanations. Pick 10–120 questions per session. Filter by domain to drill your weak areas.
Go to practice testEvery CKSterm defined and searchable. Use it when a chapter mentions a concept you haven't seen before or want a quick refresher on.
Browse glossaryExam blueprint, domain weights, passing score, duration, cost, and registration links. Start here if you're new to this certification.
View exam guideKubernetes Security Fundamentals
Objective 1.1 · Understand the Kubernetes security model and threat landscape
Cluster Setup: Secure Configuration and Best Practices
Objective 1.2 · Apply secure cluster setup and configuration
TLS Certificates and API Server Security
Objective 1.3 · Secure Kubernetes API server with TLS certificates and authentication
RBAC, Service Accounts, and IAM
Objective 1.4 · Implement role-based access control and manage service accounts
Supply Chain Security: Container Image Security
Objective 2.1 · Secure container images, registries, and image scanning
Supply Chain Security: Policy Enforcement and Admission Controllers
Objective 2.2 · Implement admission controllers and policy engines (e.g., OPA/Gatekeeper, Kyverno)
Supply Chain Security: Secrets Management and Encryption
Objective 2.3 · Manage secrets securely at rest and in transit
Cluster Hardening: Node and Container Security
Objective 3.1 · Harden nodes, containers, and pod security policies
Cluster Hardening: Resource Quotas and Limit Ranges
Objective 3.3 · Apply resource quotas and limit ranges to prevent resource exhaustion
System Hardening: Host OS and Kernel Security
Objective 4.1 · Harden the underlying host operating system and kernel parameters
System Hardening: CIS Benchmarks and Auditing
Objective 4.2 · Apply CIS benchmarks for Kubernetes and conduct security audits
Microservice Vulnerabilities: Pod Security Standards
Objective 5.1 · Implement Pod Security Standards (Baseline, Restricted)
Microservice Vulnerabilities: Secure Deployments and Runtime
Objective 5.2 · Secure microservice deployments using runtime security tools (e.g., Falco, AppArmor, Seccomp)
Monitoring and Runtime: Logging and Auditing
Objective 6.1 · Configure logging, auditing, and monitoring for security events
Monitoring and Runtime: Threat Detection and Incident Response
Objective 6.2 · Implement threat detection, forensics, and incident response for Kubernetes
Free CKS practice questions with full explanations. Test what you learn chapter by chapter.
CKS Practice Questions