Skip to content

Kubernetes and Cloud Native Security Associate (KCSA)

A multiple-choice, associate-level certification covering the Kubernetes threat model, cluster component security, authentication and authorization, network policy, supply chain and compliance frameworks.

The Linux Foundation / CNCF
Exam cost
$250 USD (includes one free retake)
src
Linux Foundation Training & Certification — Kubernetes and Cloud Native Security Associate (KCSA) certification page (training.linuxfoundation.org)
chk
Duration
90 minutes
Passing score
75%
Valid for
2 years

The KCSA is the entry point to the CNCF's security ladder, and the thing worth knowing before you book it is that it is not a smaller CKS. It is a different kind of exam entirely.

KCSA against CKS

The CKS is performance-based: a live cluster, a clock, documentation open in a browser, and a passed CKA required before you are allowed to sit it. The KCSA is 90 minutes of closed-book multiple choice with no cluster and no prerequisites at all.

So they test different things. The KCSA asks whether you understand the threat model — what the API server trusts, where the trust boundaries fall, how privilege escalates. The CKS asks whether you can harden a cluster while someone times you.

Passing the KCSA does not exempt you from anything. It is not a prerequisite for the CKS and it does not replace the CKA requirement.

Where the marks are

There is no dominant domain, which is the defining feature of this exam. Cluster Component Security and Security Fundamentals are 22% each; the Threat Model and Platform Security are 16% each; the cloud native overview is 14% and compliance is 10%.

Six domains and no concentration means there is nowhere to specialise and nothing safe to skip. Plan for breadth.

The domain most people underestimate is the Kubernetes Threat Model. Candidates arriving from platform or operations work know the components well and have rarely been asked to reason about them adversarially — persistence, denial of service, privilege escalation. It is a different habit applied to a familiar system, and 16% of the marks depend on it.

Who it is genuinely for

Security engineers moving into Kubernetes. That direction is where the exam pays: strong identity and network instincts, a shallow model of what a cluster trusts, and this syllabus maps that gap almost exactly.

The reverse direction is weaker. If you already run clusters daily, the KCSA will largely confirm what you know, and the CKS is the more credible signal for the same money and a fraction more work.

Before you book

Closed book. No cluster, no documentation, no browser — the opposite of the CKA and CKS. Precise vocabulary matters here: Pod Security Standards and Pod Security Admission are different things, and the exam knows it.

Everything it tests is free on kubernetes.io. There is no material advantage to paid training, which makes this a test of careful reading.

$250 with a free retake, valid two years. Renewal means sitting the current exam again before it expires.

New to Linux and the command line?

This path assumes fundamentals you may not have yet. Our Foundations Pack is out and free — Linux, the shell and Git, with exercises that mark your work and explain why you got it wrong. We're writing an agents pack next; leave your email if you want to hear when it ships.

One email when the pack launches. No spam, unsubscribe any time.

Your progress0%

Exam domains

Kubernetes Cluster Component Security

22%
API ServerController ManagerSchedulerKubeletContainer RuntimeKubeProxyPodEtcdContainer NetworkingClient SecurityStorage

Kubernetes Security Fundamentals

22%
Pod Security StandardsPod Security AdmissionsAuthenticationAuthorizationSecretsIsolation and SegmentationAudit LoggingNetwork Policy

Kubernetes Threat Model

16%
Kubernetes Trust Boundaries and Data FlowPersistenceDenial of ServiceMalicious Code Execution and Compromised Applications in ContainersAttacker on the NetworkAccess to Sensitive DataPrivilege Escalation

Platform Security

16%
Supply Chain SecurityImage RepositoryObservabilityService MeshPKIConnectivityAdmission Control

Overview of Cloud Native Security

14%
The 4Cs of Cloud Native SecurityCloud Provider and Infrastructure SecurityControls and FrameworksIsolation TechniquesArtifact Repository and Image SecurityWorkload and Application Code Security

Compliance and Security Frameworks

10%
Compliance FrameworksThreat Modelling FrameworksSupply Chain ComplianceAutomation and Tooling

Preparation path

  1. 1

    Learn what each control plane component trusts

    The heaviest domain at 22%, and it is architecture rather than configuration — what the API server authenticates, why etcd is the crown jewels, what the kubelet will accept. Read the architecture docs asking what an attacker reaching this component would gain.

    ~12 hours
  2. 2

    Work through authentication, authorization and the Pod Security Standards

    The other 22% domain, and the one with the most precise vocabulary. Privileged, baseline and restricted are exact terms with exact contents, and Pod Security Admission is not the same thing as Pod Security Standards — questions turn on that distinction.

    ~14 hours
  3. 3

    Read the Kubernetes threat model as a threat model

    Trust boundaries, persistence, privilege escalation, denial of service. This 16% domain is the one candidates from an operations background find least familiar, because it asks you to reason as an attacker about a system you normally reason about as an operator.

    ~10 hours
  4. 4

    Cover supply chain, admission control and audit logging

    Platform Security is 16% and Compliance another 10%, and together they are the material an operations engineer is least likely to have absorbed by accident. Image provenance, admission webhooks and what an audit policy actually records are the recurring subjects.

    ~10 hours

Frequently asked questions

Career Roadmaps