Certified Kubernetes Security Specialist assessment
Remote-proctored or provider-controlled performance assessment using practical tasks and an exam environment.
- Type
- Practical
- Delivery
- Online
- Duration
- 120 min
Exam sections
Cluster Setup
This area examines how candidates work with cluster setup when requirements, constraints, and expected outcomes must be reconciled. The official competency detail includes Use Network security policies to restrict cluster level access; Use CIS benchmark to review the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi); Properly set up Ingress with TLS; Protect node metadata and endpoints; Verify platform binaries before deploying.
Question notes
A candidate working through Cluster Setup should remember that expect Cluster Setup to appear through choices, scenarios, or tasks that require application rather than simple recall. No section-specific question count or timing is assumed unless the provider publishes one.
Preparation tips
Turn every major objective in Cluster Setup into a decision question. Explain the preferred option, the risk in the strongest alternative, and the observation or artifact that would verify success. Keep the resulting notes under the Cluster Setup heading so gaps remain visible during mixed review.
Cluster Hardening
The Cluster Hardening domain focuses on the concepts, actions, and judgment needed to use this part of the discipline effectively. The official competency detail includes Use Role Based Access Controls to minimize exposure; Exercise caution in using service accounts e.g. disable defaults, minimize permissions on newly created ones; Restrict access to Kubernetes API; Upgrade Kubernetes to avoid vulnerabilities.
Question notes
For Cluster Hardening, prepare for applied interpretation: a familiar term may be embedded in a design, troubleshooting, governance, investigation, or implementation situation where several answers appear plausible.
Preparation tips
Explain this domain aloud as if handing work to a colleague. Include prerequisites, common mistakes, security or governance implications, and how you would test that the result meets its objective. A final self-check should explain why Cluster Hardening matters to the candidate profile for this credential.
System Hardening
This area examines how candidates work with system hardening when requirements, constraints, and expected outcomes must be reconciled. The official competency detail includes Minimize host OS footprint (reduce attack surface); Using least-privilege identity and access management; Minimize external access to the network; Appropriately use kernel hardening tools such as AppArmor, seccomp.
Question notes
When Certified Kubernetes Security Specialist reaches System Hardening, expect System Hardening to appear through choices, scenarios, or tasks that require application rather than simple recall. No section-specific question count or timing is assumed unless the provider publishes one.
Preparation tips
Alternate focused review with mixed-domain practice. The mixed sessions are important because System Hardening is likely to interact with other responsibilities rather than remain an isolated fact set. Keep the resulting notes under the System Hardening heading so gaps remain visible during mixed review.
Minimize Microservice Vulnerabilities
The Minimize Microservice Vulnerabilities domain focuses on the concepts, actions, and judgment needed to use this part of the discipline effectively. The official competency detail includes Use appropriate pod security standards; Manage Kubernetes secrets; Understand and implement isolation techniques (multi-tenancy, sandboxed containers, etc.); Implement Pod-to-Pod encryption (Cilium, Istio).
Question notes
Within the Minimize Microservice Vulnerabilities objectives, expect Minimize Microservice Vulnerabilities to appear through choices, scenarios, or tasks that require application rather than simple recall. No section-specific question count or timing is assumed unless the provider publishes one.
Preparation tips
Use official terminology as an index, then attach each term to an action, example, counterexample, and verification method. Revisit weak explanations until they no longer depend on memorized wording. Keep the resulting notes under the Minimize Microservice Vulnerabilities heading so gaps remain visible during mixed review.
Supply Chain Security
The scope of Supply Chain Security includes both understanding the subject and choosing an effective response when conditions or objectives change. The official competency detail includes Minimize base image footprint; Understand your supply chain (e.g. SBOM, CI/CD, artifact repositories); Secure your supply chain (permitted registries, sign and validate artifacts, etc.); Perform static analysis of user workloads and container images (e.g. Kubesec, KubeLinter).
Question notes
In the context of Certified Kubernetes Security Specialist, the Supply Chain Security objectives indicate that the section is modeled as a blueprint domain rather than a separately timed exam part. Its concepts can still influence questions or tasks elsewhere in the assessment.
Preparation tips
Explain this domain aloud as if handing work to a colleague. Include prerequisites, common mistakes, security or governance implications, and how you would test that the result meets its objective. Use Certified Kubernetes Security Specialist and the Supply Chain Security heading as the boundary for deciding how deeply to pursue adjacent material.
Monitoring, Logging and Runtime Security
This area examines how candidates work with monitoring, logging and runtime security when requirements, constraints, and expected outcomes must be reconciled. The official competency detail includes Perform behavioral analytics to detect malicious activities; Detect threats within physical infrastructure, apps, networks, data, users and workloads; Investigate and identify phases of attack and bad actors within the environment; Ensure immutability of containers at runtime; Use Kubernetes audit logs to monitor access.
Question notes
Within the Monitoring, Logging and Runtime Security objectives, this domain may be assessed independently or as part of a scenario crossing other blueprint areas. Pay attention to the wording that changes scope, responsibility, risk, or the best next action.
Preparation tips
Create a one-page model of how Monitoring, Logging and Runtime Security connects to the preceding and following domains. Use scenario questions to rehearse boundary decisions and identify when another specialist or control is needed. Use Certified Kubernetes Security Specialist and the Monitoring, Logging and Runtime Security heading as the boundary for deciding how deeply to pursue adjacent material.
