CNCF / Linux Foundation

Certified Kubernetes Security Specialist

Harden a cluster, and prove the hardening holds.

Exam code
CKS
Duration
2 hours
Pass mark
67%
Valid for
2 years
Typical preparation
8 to 12 weeks
Retake
One free retake included with the exam

What the exam actually is

The CKS is the hardest of the three and the only one with a prerequisite: an active CKA. It assumes you can already operate a cluster, then asks whether you can secure it. Expect admission control, runtime policy, image supply chain and audit logging, all under the same two-hour clock.

Who it is for

  • Platform and security engineers responsible for cluster posture
  • CKA holders moving into a security-focused role
  • Consultants advising on Kubernetes compliance and hardening

Prerequisites

An active CKA certification is required to sit the exam. Beyond that, real familiarity with Linux security primitives is expected.

Where candidates lose points

  • The toolchain is wide: Falco, Trivy, AppArmor, seccomp, OPA or Kyverno, audit policy
  • Knowing which tool a question wants is half the battle; practise recognising the signal
  • API server flags and admission controller configuration are recurring themes
  • The prerequisite CKA must still be valid on the day you sit the exam

Why it is worth doing

Security roles are where Kubernetes budgets are moving, and the CKS is currently the only vendor-neutral proof that you can do the work rather than run a scanner.

Official CKS page — always the authority on price, format and validity.

Preparing for CKS on a deadline?

Practise against the official domain weights, and get told when a CKS discount appears instead of paying full price.