CNCF / Linux Foundation
Certified Kubernetes Security Specialist
Harden a cluster, and prove the hardening holds.
- Exam code
- CKS
- Duration
- 2 hours
- Pass mark
- 67%
- Valid for
- 2 years
- Typical preparation
- 8 to 12 weeks
- Retake
- One free retake included with the exam
What the exam actually is
The CKS is the hardest of the three and the only one with a prerequisite: an active CKA. It assumes you can already operate a cluster, then asks whether you can secure it. Expect admission control, runtime policy, image supply chain and audit logging, all under the same two-hour clock.
Who it is for
- Platform and security engineers responsible for cluster posture
- CKA holders moving into a security-focused role
- Consultants advising on Kubernetes compliance and hardening
Prerequisites
An active CKA certification is required to sit the exam. Beyond that, real familiarity with Linux security primitives is expected.
Where candidates lose points
- The toolchain is wide: Falco, Trivy, AppArmor, seccomp, OPA or Kyverno, audit policy
- Knowing which tool a question wants is half the battle; practise recognising the signal
- API server flags and admission controller configuration are recurring themes
- The prerequisite CKA must still be valid on the day you sit the exam
Why it is worth doing
Security roles are where Kubernetes budgets are moving, and the CKS is currently the only vendor-neutral proof that you can do the work rather than run a scanner.
Official CKS page — always the authority on price, format and validity.
Preparing for CKS on a deadline?
Practise against the official domain weights, and get told when a CKS discount appears instead of paying full price.