CertGrid CertGrid

CKS (Certified Kubernetes Security Specialist)

Hardening, supply chain, runtime and audit.

40 published guides

32 of 40 guides need path access. Unlock CKS path

40-guide Certified Kubernetes Security Specialist learning path · 40 published · about 668 min of reading · 9 learning tracks · reviewed 25 August 2026

Orientation3 guides

What CKS asks, why a valid CKA is a prerequisite, and the clusters used.

  1. Concepts 12 min

    CKS Exam Format and Domain Weights

    Six domains, two hours of tasks, 67% - and a CKA you must already hold.

    All six domains

    Updated 25 Aug 2026

  2. Concepts 11 min

    Moving from KCSA to CKS

    Twenty terms counted across both banks, and the four where CKS is on ground KCSA never walks.

    All six domains

    Updated 25 Aug 2026

  3. Hands-on Lab 14 min

    The CKS Practice Clusters

    Three clusters, one of them deliberately untainted - and an encryption setting that is a task rather than a fact.

    All six domains

    Updated 25 Aug 2026

Cluster Setup5 guides

Network policy, CIS benchmarks, ingress TLS, node metadata protection. 15%.

  1. Hands-on Lab 20 min

    NetworkPolicy for Cluster-Level Access Control

    Four states, each one measured: open, denied, DNS back, and exactly one thing allowed.

    Domain 1 - Cluster Setup (15%)

    Updated 25 Aug 2026

  2. Hands-on Lab 19 min

    CIS Benchmark Review with kube-bench

    One finding fixed and measured - and one that will not clear no matter what you chmod.

    Domain 1 - Cluster Setup (15%)

    Updated 25 Aug 2026

  3. Hands-on Lab 20 min

    Ingress TLS Configuration

    Install a controller, mint a certificate, and read the certificate the server actually served.

    Domain 1 - Cluster Setup (15%)

    Updated 25 Aug 2026

  4. Hands-on Lab 18 min

    Protecting Node Metadata and Endpoints

    The kubelet answers 401 from inside a Pod - and nothing at all after one egress rule.

    Domain 1 - Cluster Setup (15%)

    Updated 25 Aug 2026

  5. Hands-on Lab 14 min

    Verifying Kubernetes Platform Binaries

    A digest that matches, one byte that breaks it, and the thing a checksum cannot prove.

    Domain 1 - Cluster Setup (15%)

    Updated 25 Aug 2026

Cluster Hardening5 guides

RBAC minimisation, ServiceAccounts, apiserver exposure, keeping up with releases. 15%.

  1. Hands-on Lab 18 min Paid

    Minimizing an Over-Broad RBAC Role

    A wildcard Role replaced with two narrow ones - and tested in both directions.

    Domain 2 - Cluster Hardening (15%)

    Updated 25 Aug 2026

  2. Hands-on Lab 16 min Paid

    Auditing RBAC Permissions

    Six read-only queries that give you a cluster's RBAC posture, and a baseline to compare next quarter against.

    Domain 2 - Cluster Hardening (15%)

    Updated 25 Aug 2026

  3. Hands-on Lab 17 min Paid

    ServiceAccount Tokens and automountServiceAccountToken

    Turn the default credential off for a whole namespace, then hand one back on purpose.

    Domain 2 - Cluster Hardening (15%)

    Updated 25 Aug 2026

  4. Hands-on Lab 18 min Paid

    Restricting Kubernetes API Access

    200 without a credential, 403 as system:anonymous - and every Pod can reach the control plane until you stop it.

    Domain 2 - Cluster Hardening (15%)

    Updated 25 Aug 2026

  5. Hands-on Lab 22 min Paid

    Upgrading Kubernetes to Patch Vulnerabilities

    A real upgrade, on a real cluster, checked after every phase - and the step that makes people stop too early.

    Domain 2 - Cluster Hardening (15%)

    Updated 25 Aug 2026

System Hardening4 guides

Host OS footprint, IAM roles, kernel attack surface, AppArmor and seccomp. 10%.

  1. Hands-on Lab 17 min Paid

    Minimizing the Host OS Footprint

    Ten open ports, 765 packages and a kernel that will still load modules - measured, then judged.

    Domain 3 - System Hardening (10%)

    Updated 25 Aug 2026

  2. Hands-on Lab 15 min Paid

    Least-Privilege Identity and Access on the Node

    Two shells, one NOPASSWD line, and four checks this node fails three of.

    Domain 3 - System Hardening (10%)

    Updated 25 Aug 2026

  3. Hands-on Lab 18 min Paid

    Restricting Node External Network Access

    An unauthenticated metrics port handing out the kernel version - found, closed, and the kubelet left untouched.

    Domain 3 - System Hardening (10%)

    Updated 25 Aug 2026

  4. Hands-on Lab 22 min Paid

    AppArmor and seccomp Profiles for Pods

    Two identical Pods, one file write, one Permission denied - and a syscall that stops working.

    Domain 3 - System Hardening (10%)

    Updated 25 Aug 2026

Microservice Vulnerabilities7 guides

Security contexts, Pod Security, Secrets, sandboxing and mTLS. 20%.

  1. Hands-on Lab 17 min Paid

    Pod Security Admission: enforce, audit and warn

    Warn, audit, then enforce - and the privileged Pod that carries on running through all three.

    Domain 4 - Minimize Microservice Vulnerabilities (20%)

    Updated 25 Aug 2026

  2. Hands-on Lab 18 min Paid

    A securityContext That Passes the Restricted Standard

    Four refusals turned into four fields, each one proved from inside the container.

    Domain 4 - Minimize Microservice Vulnerabilities (20%)

    Updated 25 Aug 2026

  3. Hands-on Lab 22 min Paid

    Encrypting Secrets at Rest in etcd

    A card number readable in etcd, then ciphertext - and the Secrets that stay readable until you rewrite them.

    Domain 4 - Minimize Microservice Vulnerabilities (20%)

    Updated 25 Aug 2026

  4. Hands-on Lab 16 min Paid

    Managing Kubernetes Secrets

    The same Secret two ways, and only one of them is in /proc.

    Domain 4 - Minimize Microservice Vulnerabilities (20%)

    Updated 25 Aug 2026

  5. Hands-on Lab 20 min Paid

    Namespace Isolation for Multi-Tenancy

    Six objects, tested from both directions - and the boundary they still cannot draw.

    Domain 4 - Minimize Microservice Vulnerabilities (20%)

    Updated 25 Aug 2026

  6. Hands-on Lab 16 min Paid

    Sandboxed Containers with gVisor and RuntimeClass

    A container that reports a different kernel from the machine it is running on.

    Domain 4 - Minimize Microservice Vulnerabilities (20%)

    Updated 25 Aug 2026

  7. Hands-on Lab 20 min Paid

    Pod-to-Pod Encryption with Cilium WireGuard

    A canary string read off the wire with tcpdump - and then 104 packets with none of it.

    Domain 4 - Minimize Microservice Vulnerabilities (20%)

    Updated 25 Aug 2026

Supply Chain Security7 guides

Base image footprint, image signing, allowed registries, static analysis, scanning. 20%.

  1. Hands-on Lab 16 min Paid

    Minimizing the Base Image Footprint

    Ninety components down to one, and 175 findings down to none - without patching anything.

    Domain 5 - Supply Chain Security (20%)

    Updated 25 Aug 2026

  2. Hands-on Lab 15 min Paid

    Software Bills of Materials (SBOM)

    An inventory you can scan a year later without ever fetching the image again.

    Domain 5 - Supply Chain Security (20%)

    Updated 25 Aug 2026

  3. Hands-on Lab 15 min Paid

    Container Scanning and Vulnerability Staleness

    175 findings, none of them fixable - and the flag that turns a scanner into a gate people keep.

    Domain 5 - Supply Chain Security (20%)

    Updated 25 Aug 2026

  4. Hands-on Lab 16 min Paid

    Restricting Permitted Image Registries

    Two CEL rules, two different refusals - and one thing neither of them can see.

    Domain 5 - Supply Chain Security (20%)

    Updated 25 Aug 2026

  5. Hands-on Lab 18 min Paid

    Signing and Verifying Artifacts with Cosign

    Verified OK - then one character changes and it is not.

    Domain 5 - Supply Chain Security (20%)

    Updated 25 Aug 2026

  6. Hands-on Lab 15 min Paid

    Static Analysis of Kubernetes Manifests

    Five findings with identifiers, before a cluster is involved at all.

    Domain 5 - Supply Chain Security (20%)

    Updated 25 Aug 2026

  7. Hands-on Lab 14 min Paid

    Static Analysis of a Dockerfile

    Five findings in six lines - including the missing USER that everything downstream compensates for.

    Domain 5 - Supply Chain Security (20%)

    Updated 25 Aug 2026

Monitoring and Runtime7 guides

Behavioural analytics, immutability at runtime, and the audit log. 20%.

  1. Hands-on Lab 18 min Paid

    Enabling Kubernetes Audit Logging

    The only record that can name a caller, and the policy file that decides what it costs you.

    Domain 6 - Monitoring, Logging and Runtime Security (20%)

    Updated 25 Aug 2026

  2. Hands-on Lab 18 min Paid

    Querying Kubernetes Audit Logs

    Who read the Secret, and who ran the exec - the two questions nothing else in the cluster can answer.

    Domain 6 - Monitoring, Logging and Runtime Security (20%)

    Updated 25 Aug 2026

  3. Hands-on Lab 14 min Paid

    Container Immutability at Runtime

    One field, and the binary that is running can no longer be replaced underneath it.

    Domain 6 - Monitoring, Logging and Runtime Security (20%)

    Updated 25 Aug 2026

  4. Hands-on Lab 16 min Paid

    Falco Runtime Detection and Resource Limits

    The probe loads, the engine opens, and then the node runs out of memory - which is the finding.

    Domain 6 - Monitoring, Logging and Runtime Security (20%)

    Updated 25 Aug 2026

  5. Hands-on Lab 17 min Paid

    Identifying the Phases of an Attack

    Discovery, lateral movement, and the reach for the data - two of the three succeed.

    Domain 6 - Monitoring, Logging and Runtime Security (20%)

    Updated 25 Aug 2026

  6. Hands-on Lab 15 min Paid

    Threat Detection Across Cluster Layers

    One exec, five places to look for it, and three of them say no.

    Domain 6 - Monitoring, Logging and Runtime Security (20%)

    Updated 25 Aug 2026

  7. Hands-on Lab 14 min Paid

    Assessing Cluster Detection Coverage

    The honest inventory at the end of the path: two of four, and neither on purpose.

    Domain 6 - Monitoring, Logging and Runtime Security (20%)

    Updated 25 Aug 2026

Working at Exam Speed2 guides

15-20 tasks in 120 minutes on a live cluster, and what the grader reads.

  1. Hands-on Lab 15 min Paid

    Common CKS Task Mistakes

    Five commands that all said they worked, and none of which did what the task asked.

    All six domains

    Updated 25 Aug 2026

  2. Hands-on Lab 12 min Paid

    Time Management on a Performance Exam

    Four measurements on a real cluster, and the one that is longer than the other three together.

    All six domains

    Updated 25 Aug 2026

Command Cheat Sheets1 sheet

Searchable references for the tools CKS expects you to drive.

← Back to Learn