Cluster Setup & Hardening (30%)
Network policies, CIS benchmarks, ingress security, RBAC, service accounts, and restricting API access. The combined weight of these two domains makes them the foundation of the exam.
Master Kubernetes security from cluster hardening to runtime defense. A comprehensive, hands-on guide to passing the CKS exam with confidence.
The following mind map shows the complete breakdown of CKS exam domains, their weight percentages, and the key topics within each domain.
This study guide is structured to take you from foundational Kubernetes security concepts all the way through exam-ready proficiency. Each section maps directly to the official CKS curriculum and includes:
Before starting this guide, you should hold an active CKA (Certified Kubernetes Administrator) certification or have equivalent experience. The CKS exam assumes working knowledge of:
kubectl proficiency and resource managementSee the Prerequisites section for a detailed readiness checklist.
| Detail | Information |
|---|---|
| Certification Name | Certified Kubernetes Security Specialist (CKS) |
| Exam Duration | 2 hours |
| Format | Performance-based (hands-on, command-line tasks) |
| Passing Score | 67% |
| Proctoring | PSI Bridge Proctored |
| Environment | Remote desktop with terminal access to Kubernetes clusters |
| Prerequisites | Active CKA certification required |
| Validity | 2 years from date of certification |
| Retakes | 1 free retake included with exam purchase |
| Kubernetes Version | Aligned with latest stable release at time of exam |
| Allowed Resources | Kubernetes documentation (kubernetes.io), tool docs during exam |
| Domain | Weight |
|---|---|
| Cluster Setup | 15% |
| Cluster Hardening | 15% |
| System Hardening | 15% |
| Minimize Microservice Vulnerabilities | 20% |
| Supply Chain Security | 20% |
| Monitoring, Logging and Runtime Security | 15% |
Exam Strategy: The two highest-weighted domains -- Minimize Microservice Vulnerabilities and Supply Chain Security -- together account for 40% of the exam. Prioritize deep understanding and hands-on practice in these areas while maintaining solid coverage across all domains.
Built with VitePress -- Powered by OpsAlchemy