Certification guideCKS

Certified Kubernetes Security Specialist: the honest guide

Everything Linux Foundation / CNCF publishes about CKS, in one place: what the exam asks, how the domains are weighted, and what it takes to be ready.

This guide page is built from the registry, not written yet.

Everything below comes from CKS’s published exam data, and every figure links to the vendor page it came from. The researched version, with study plans and the parts nobody publishes, is still being written. This page is not submitted to search engines until it is.

Practise CKS questions in the meantime

What the exam actually asks you to do

Entirely hands-on: tasks in a terminal against live clusters, open book against allowed documentation. No multiple choice at all.

  • Performance-based

The highlighted formats are the ones you cannot answer from memory alone. Linux Foundation, CKS exam details

Domain breakdown and official weightings

From the official published CNCF curriculum. Minimize Microservice Vulnerabilities is the heaviest domain at 20 percent, followed by Supply Chain Security at 20 percent.

  • Cluster Setup15%
  • Cluster Hardening15%
  • System Hardening10%
  • Minimize Microservice Vulnerabilities20%
  • Supply Chain Security20%
  • Monitoring, Logging and Runtime Security20%

Linux Foundation / CNCF: published CNCF curriculum

What comes after passing

CKS lasts two years. Renewal means passing the current exam again, though the Linux Foundation discounts exams heavily and often.

Costs across the full renewal cycle are on the CKS cost page.

Frequently asked questions

Do I need CKA before CKS?

Yes, and formally: sitting CKS requires a current, non-expired CKA certification. That prerequisite is the Linux Foundation's rule rather than advice, so plan the pair in order.

How does CKS differ in difficulty from CKA?

Same terminal format, narrower and deeper content. Expect AppArmor and seccomp profiles, admission control, NetworkPolicies, image scanning and runtime detection with tools like Falco, all under the same clock pressure.

Which CKS domains carry the most weight?

Three tie at 20 percent: minimizing microservice vulnerabilities, supply chain security, and monitoring with runtime security. Together with hardening they are the exam; pure cluster setup is only 15 percent.

Keep reading

Every guide and cost breakdown, by vendor

Practise CKS for free while you decide

Original questions written from the published objectives, with the concept, the reasoning, and a note on every wrong option. No account needed to start.

Start free CKS questions