Secure Kubernetes from cluster configuration to application runtime with hands-on cloud-native security skills.

The Certified Kubernetes Security Specialist (CKS) program develops the practical expertise to secure container-based applications and Kubernetes platforms across their lifecycle.

Learn to harden clusters and host systems, enforce workload security, protect the software supply chain, manage vulnerabilities, and detect threats while preparing for CNCF and The Linux Foundation’s performance-based CKS certification.

  • Why get trained: Strengthen Kubernetes security across clusters, workloads, access, supply chains, and runtime environments
  • Why it matters: Kubernetes security requires protection across configuration, infrastructure, applications, software artifacts, and active workloads
  • Who should attend: DevOps engineers, Kubernetes administrators, cloud security engineers, and IT professionals

Apply security throughout the Kubernetes lifecycle to reduce attack surfaces, protect workloads, and respond more effectively to cloud-native threats. HRD Corp Claimable.

Overview

The CKS was created by the Linux Foundation and the Cloud Native Computing Foundation (CNCF) as a part of their ongoing effort to help develop the Kubernetes ecosystem. The exam is online, proctored, performance-based test that requires solving multiple tasks from a command line running Kubernetes.

Once enrolled you will receive access to an exam simulator, provided by Killer.sh, allowing you to experience the exam environment. You will have two simulation attempts (36 hours of access for each attempt from the start of activation). The simulation includes 20-25 questions that are exactly the same for every attempt and every user, unlike the actual exam. The simulation will provide graded results.

Skills Covered

  • Proves High-Demand Security Skills
  • Career Advancement
  • Industry-wide Credential Recognition
  • Networking Opportunities

Prerequisites

Target Audience

  • DevOps engineers
  • Kubernetes administrators
  • Cloud security engineers
  • IT professionals

Course Curriculum

Module 1: Cluster Setup

  • Use Network security policies to restrict cluster level access
  • Use CIS benchmark to review the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
  • Properly set up Ingress with TLS
  • Protect node metadata and endpoints
  • Verify platform binaries before deploying

Module 2: Cluster Hardening

  • Use Role Based Access Controls to minimize exposure
  • Exercise caution in using service accounts e.g. disable defaults, minimize permissions on newly created ones
  • Restrict access to Kubernetes API
  • Upgrade Kubernetes to avoid vulnerabilities

Module 3: System Hardening

  • Minimize host OS footprint (reduce attack surface)
  • Using least-privilege identity and access management
  • Minimize external access to the network
  • Appropriately use kernel hardening tools such as AppArmor, seccomp

Module 4: Minimize Microservice Vulnerabilities

  • Use appropriate pod security standards
  • Manage Kubernetes secrets
  • Understand and implement isolation techniques (multi-tenancy, sandboxed containers, etc.)
  • Implement Pod-to-Pod encryption using Cilium

Module 5: Supply Chain Security

  • Minimize base image footprint
  • Understand your supply chain (e.g. SBOM, CI/CD, artifact repositories)
  • Secure your supply chain (permitted registries, sign and validate artifacts, etc.)
  • Perform static analysis of user workloads and container images (e.g. Kubesec, KubeLinter)

Module 6: Monitoring, Logging and Runtime Security

  • Perform behavioral analytics to detect malicious activities
  • Detect threats within physical infrastructure, apps, networks, data, users and workloads
  • Investigate and identify phases of attack and bad actors within the environment
  • Ensure immutability of containers at runtime
  • Use Kubernetes audit logs to monitor access

Dates & Locations

Let’s make it work for you

Can’t find a date that fits? Need to train your whole team? Looking for a discount?
Speak to one of our learning experts today.

November 16, 2026 - November 19, 2026

Location: Kuala Lumpur
Modal: ILT
Availability: TBC
Exam:
RM 2003

November 16, 2026 - November 19, 2026

Location: Online
Modal: VILT
Availability: TBC
Exam:
RM 2003

February 9, 2027 - February 12, 2027

Location: Kuala Lumpur
Modal: ILT
Availability: TBC
Exam:
RM 2003

February 9, 2027 - February 12, 2027

Location: Online
Modal: VILT
Availability: TBC
Exam:
RM 2003

April 13, 2027 - April 16, 2027

Location: Kuala Lumpur
Modal: ILT
Availability: TBC
Exam:
RM 2003

April 13, 2027 - April 16, 2027

Location: Online
Modal: VILT
Availability: TBC
Exam:
RM 2003

June 15, 2027 - June 18, 2027

Location: Kuala Lumpur
Modal: ILT
Availability: TBC
Exam:
RM 2003

June 15, 2027 - June 18, 2027

Location: Online
Modal: VILT
Availability: TBC
Exam:
RM 2003

August 17, 2027 - August 20, 2027

Location: Kuala Lumpur
Modal: ILT
Availability: TBC
Exam:
RM 2003

August 17, 2027 - August 20, 2027

Location: Online
Modal: VILT
Availability: TBC
Exam:
RM 2003

October 18, 2027 - October 21, 2027

Location: Kuala Lumpur
Modal: ILT
Availability: TBC
Exam:
RM 2003

October 18, 2027 - October 21, 2027

Location: Online
Modal: VILT
Availability: TBC
Exam:
RM 2003

December 14, 2027 - December 17, 2027

Location: Kuala Lumpur
Modal: ILT
Availability: TBC
Exam:
RM 2003

December 14, 2027 - December 17, 2027

Location: Online
Modal: VILT
Availability: TBC
Exam:
RM 2003
Trainocate exam and cert

Exam & Certification

This exam is an online, proctored, performance-based test that requires solving multiple tasks from a command line running Kubernetes. Candidates have 2 hours to complete the tasks. Certified Kubernetes Security Specialist (CKS) candidates must have taken and passed the Certified Kubernetes Administrator (CKA) exam prior to attempting the CKS exam.

Training & Certification Guide

This exam is an online, proctored, performance-based test that requires solving multiple tasks from a command line running Kubernetes.

Candidates have 2 hours to complete the tasks. Certified Kubernetes Security Specialist (CKS) candidates must have taken and passed the Certified Kubernetes Administrator (CKA) exam prior to attempting the CKS exam.

The CKS was created by the Linux Foundation and the Cloud Native Computing Foundation (CNCF) as a part of their ongoing effort to help develop the Kubernetes ecosystem. The exam is online, proctored, performance-based test that requires solving multiple tasks from a command line running Kubernetes.

Frequently Asked Questions

You will learn how to secure Kubernetes clusters, workloads, container supply chains, and runtime environments using practical cloud-native security techniques.

The course addresses Kubernetes security throughout the application and infrastructure lifecycle. You will learn how to:

  • Secure cluster configuration and network access
  • Harden Kubernetes components and host systems
  • Apply RBAC and least-privilege access
  • Protect secrets and workloads
  • Implement Pod Security Standards
  • Apply workload isolation techniques
  • Secure container images and software supply chains
  • Use SBOMs and artifact validation
  • Monitor Kubernetes audit logs
  • Detect malicious runtime activity

These areas align closely with the competencies currently assessed by the CKS certification.

Pro Tip: Approach Kubernetes security as a lifecycle rather than a single configuration task. CKS tests security across build, deployment, cluster configuration, and runtime operations.

CKS is ideal if you already work with Kubernetes and want to specialize in securing containerized applications and Kubernetes infrastructure.

This course is particularly relevant for:

  • Kubernetes Administrators
  • DevOps Engineers
  • DevSecOps Engineers
  • Cloud Security Engineers
  • Platform Engineers
  • Site Reliability Engineers
  • Security Engineers

Unlike general Kubernetes administration training, CKS concentrates specifically on protecting Kubernetes environments and container-based applications during build, deployment, and runtime.

Pro Tip: If your current responsibilities include both Kubernetes administration and security, CKS is a natural progression because it applies security practices directly to the platform you already manage.

Yes. You must have passed the Certified Kubernetes Administrator (CKA) exam before you can attempt the CKS certification exam.

This is an important distinction between taking CKS training and attempting the certification exam. CNCF requires CKS exam candidates to have previously passed CKA because CKS builds on Kubernetes administration skills rather than teaching them from the beginning.

However, your CKA certification does not need to still be active when you attempt CKS. CNCF specifically confirms that you need to have passed CKA previously.

Pro Tip: Complete CKA first if certification is your objective. Being comfortable with cluster administration, networking, workloads, storage, and troubleshooting lets you concentrate on security during CKS rather than relearning Kubernetes fundamentals.

CKA validates your ability to administer Kubernetes, while CKS validates your ability to secure Kubernetes clusters and container-based applications.

The two certifications are designed to build on one another.

CKA CKS
Kubernetes administration Kubernetes security
Cluster configuration Cluster hardening
Workloads and scheduling Workload security
Networking and services Network security policies
Storage Secrets and isolation
Troubleshooting Runtime threat detection
Platform operations Supply chain security

CKS assumes that you already possess the Kubernetes administration capabilities validated by CKA, which is why passing CKA is a prerequisite for attempting the CKS exam.

Pro Tip: Think of CKA → CKS as a progression from “Can I operate this Kubernetes environment?” to “Can I operate it securely?”

CKS is a fully performance-based exam that requires you to solve Kubernetes security tasks in a command-line environment.

There are no traditional multiple-choice questions. You have 2 hours to complete practical tasks in a simulated Kubernetes environment while being remotely proctored.

The current exam domains are:

  • Cluster Setup 10%
  • Cluster Hardening 15%
  • System Hardening 15%
  • Minimize Microservice Vulnerabilities 20%
  • Supply Chain Security 20%
  • Monitoring, Logging & Runtime Security 20%

Pro Tip: Practice performing security tasks from the command line under time pressure. Knowing what a security control does is not enough for CKS; you need to be able to implement and troubleshoot it efficiently.

Yes. Software supply chain security is a major part of both this course and the current CKS exam, accounting for 20% of the certification assessment.

The Trainocate curriculum teaches you how to:

  • Minimize container base-image footprints
  • Understand SBOMs, CI/CD, and artifact repositories
  • Restrict permitted registries
  • Sign and validate artifacts
  • Perform static analysis of workloads and container images
  • Work with tools such as Kubesec and KubeLinter

This is directly aligned with the current CKS Supply Chain Security domain, which carries a 20% exam weighting.

Pro Tip: Do not limit your exam preparation to securing running clusters. CKS expects you to understand how security starts before deployment, including the images, artifacts, and software entering your Kubernetes environment.

Yes. You will learn how to monitor Kubernetes environments, investigate suspicious activity, protect workloads at runtime, and use audit information to strengthen security.

The final curriculum module specifically addresses Monitoring, Logging and Runtime Security. It includes behavioral analytics, threat detection across infrastructure and workloads, investigation of attacks and bad actors, container immutability, and Kubernetes audit logs.

Runtime security is also a significant part of the certification itself, accounting for 20% of the current CKS exam.

Pro Tip: Practice identifying abnormal behaviour as well as configuring preventive controls. Kubernetes security requires both reducing attack opportunities and detecting when something suspicious is already happening.

Speak to a Training Consultant

All courses are HRD Claimable.
Get in touch with our team via the form or WhatsApp us on +6011-5119 6631

Preferred mode of training
Checkboxes