CertGrid CertGrid

KCSA (Kubernetes and Cloud Native Security Associate)

Cloud native threat models, the 4C model and platform hardening.

42 published guides

34 of 42 guides need path access. Unlock KCSA path

42-guide Kubernetes and Cloud Native Security Associate learning path · 42 published · about 670 min of reading · 9 learning tracks · reviewed 25 August 2026

Orientation3 guides

What KCSA asks, the 75% threshold, and the cluster it is studied on.

  1. Concepts 12 min

    KCSA Exam Format and Domain Weights

    Six domains, 60 questions, and a 75% pass mark that allows fifteen wrong answers in total.

    All six domains

    Updated 25 Aug 2026

  2. Concepts 10 min

    KCSA in the Kubernetes Certification Path

    The same subjects at three depths - counted across all three question pools rather than described.

    All six domains

    Updated 25 Aug 2026

  3. Hands-on Lab 16 min

    The KCSA Practice Cluster and Its Defaults

    A cluster rebuilt from scratch today - and the posture it starts in, measured rather than assumed.

    All six domains

    Updated 25 Aug 2026

Cloud Native Security5 guides

The 4C model - Cloud, Cluster, Container, Code - and where each control lives. 14%.

  1. Hands-on Lab 18 min

    The 4C Cloud Native Security Model

    Cloud, Cluster, Container, Code - four layers, four commands, and two answers you will not like.

    Domain 1 - Overview of Cloud Native Security (14%)

    Updated 25 Aug 2026

  2. Troubleshooting 12 min

    Cluster DNS and Service Discovery

    The same name, two tools, two answers - and why the one that fails is the one people reach for.

    Domain 1 - Overview of Cloud Native Security (14%)

    Updated 25 Aug 2026

  3. Hands-on Lab 14 min

    Pod Security Admission Levels

    One label on a namespace, and the same Pod spec stops being allowed.

    Domain 1 - Overview of Cloud Native Security (14%)

    Updated 25 Aug 2026

  4. Hands-on Lab 18 min

    Hardening a Pod with securityContext

    Five settings, each one demonstrated - including the one that does less than people think.

    Domain 1 - Overview of Cloud Native Security (14%)

    Updated 25 Aug 2026

  5. Hands-on Lab 14 min

    NetworkPolicy Default Deny and DNS

    Seven lines of YAML, and the Pod can no longer resolve a name - which is the part people are not expecting.

    Domain 1 - Overview of Cloud Native Security (14%)

    Updated 25 Aug 2026

Cluster Component Security9 guides

apiserver, etcd, kubelet, scheduler and controller-manager, one attack surface at a time. 22%.

  1. Hands-on Lab 14 min Paid

    Control Plane Static Pod Manifests

    Static Pod manifests on one node, owned by nothing, started by the kubelet before the apiserver exists.

    Domain 2 - Kubernetes Cluster Component Security (22%)

    Updated 25 Aug 2026

  2. Hands-on Lab 16 min Paid

    kube-apiserver Security Flags

    Six flags, and the one that matters most is the one that is not there.

    Domain 2 - Kubernetes Cluster Component Security (22%)

    Updated 25 Aug 2026

  3. Hands-on Lab 18 min Paid

    etcd Security and Access Control

    A Secret read out of the datastore in plaintext, and the one flag that would have stopped it.

    Domain 2 - Kubernetes Cluster Component Security (22%)

    Updated 25 Aug 2026

  4. Hands-on Lab 16 min Paid

    Kubelet API Access and Ports

    Port 10250 with its own authentication, its own authorization, and a read-only port you should check is closed.

    Domain 2 - Kubernetes Cluster Component Security (22%)

    Updated 25 Aug 2026

  5. Hands-on Lab 16 min Paid

    Node Authorization and NodeRestriction

    One certificate, one year, and a permission list that is deliberately misleading.

    Domain 2 - Kubernetes Cluster Component Security (22%)

    Updated 25 Aug 2026

  6. Hands-on Lab 14 min Paid

    Container Runtime Security

    A socket that starts containers without asking Kubernetes, and 27 containers the apiserver never mentions.

    Domain 2 - Kubernetes Cluster Component Security (22%)

    Updated 25 Aug 2026

  7. Hands-on Lab 14 min Paid

    kube-proxy and Service Implementation

    Privileged, host-networked, and a Service that turns out to be a chain of iptables rules.

    Domain 2 - Kubernetes Cluster Component Security (22%)

    Updated 25 Aug 2026

  8. Hands-on Lab 16 min Paid

    kubeconfig Files and Client Certificates

    Five kubeconfigs on one node, and the second admin file most people do not know exists.

    Domain 2 - Kubernetes Cluster Component Security (22%)

    Updated 25 Aug 2026

  9. Hands-on Lab 17 min Paid

    Storage Security: StorageClass, PV and CSI

    Delete the claim, and read the data off the node afterwards.

    Domain 2 - Kubernetes Cluster Component Security (22%)

    Updated 25 Aug 2026

Security Fundamentals8 guides

RBAC, Pod Security Admission, NetworkPolicy, Secrets and ServiceAccounts. 22%.

  1. Hands-on Lab 18 min Paid

    RBAC Fundamentals

    An identity that can do nothing, then exactly one thing - and four queries proving where the edges are.

    Domain 3 - Kubernetes Security Fundamentals (22%)

    Updated 25 Aug 2026

  2. Hands-on Lab 16 min Paid

    Projected ServiceAccount Tokens

    Audience-bound, time-limited, issued on request - and what a bearer token proves when you use one by hand.

    Domain 3 - Kubernetes Security Fundamentals (22%)

    Updated 25 Aug 2026

  3. Hands-on Lab 14 min Paid

    Privilege Escalation Paths in RBAC

    Three queries to run on any cluster you inherit - and the one binding to unauthenticated callers that is supposed to be there.

    Domain 3 - Kubernetes Security Fundamentals (22%)

    Updated 25 Aug 2026

  4. Hands-on Lab 18 min Paid

    Kubernetes Secrets and Exposure Paths

    The same Secret as an environment variable and as a file - and only one of them shows up in /proc.

    Domain 3 - Kubernetes Security Fundamentals (22%)

    Updated 25 Aug 2026

  5. Hands-on Lab 18 min Paid

    Pod Security Standards in Detail

    Two Pod specs against three namespaces - and the exact line between baseline and restricted.

    Domain 3 - Kubernetes Security Fundamentals (22%)

    Updated 25 Aug 2026

  6. Hands-on Lab 12 min Paid

    Namespaces as a Security Boundary

    A Pod pinging across a namespace boundary while RBAC refuses the same crossing.

    Domain 3 - Kubernetes Security Fundamentals (22%)

    Updated 25 Aug 2026

  7. Hands-on Lab 14 min Paid

    ResourceQuota and LimitRange as Security Controls

    A quota that makes resource requests mandatory, and then refuses the third Pod.

    Domain 3 - Kubernetes Security Fundamentals (22%)

    Updated 25 Aug 2026

  8. Concepts 14 min Paid

    Audit Logging and Cluster Records

    Events that vanish after an hour, an operational log with no caller in it, and zero audit flags.

    Domain 3 - Kubernetes Security Fundamentals (22%)

    Updated 25 Aug 2026

Kubernetes Threat Model6 guides

Thinking like the attacker: container escape, privilege escalation, lateral movement. 16%.

  1. Hands-on Lab 16 min Paid

    Trust Boundaries: Authentication and Authorization

    The same request with a token and then without one - and the 403 that names each identity by hand.

    Domain 4 - Kubernetes Threat Model (16%)

    Updated 25 Aug 2026

  2. Hands-on Lab 15 min Paid

    Network-Based Attack Vectors

    A Pod in one namespace reads an internal service in another, then stops - after one NetworkPolicy.

    Domain 4 - Kubernetes Threat Model (16%)

    Updated 25 Aug 2026

  3. Hands-on Lab 18 min Paid

    Compromised Container Blast Radius

    Root in a container that cannot mount - and a token that reads the neighbouring team's Stripe key.

    Domain 4 - Kubernetes Threat Model (16%)

    Updated 25 Aug 2026

  4. Hands-on Lab 20 min Paid

    Privilege Escalation from Pod to Node

    A ServiceAccount that cannot read a Secret reads one anyway - off the node's disk.

    Domain 4 - Kubernetes Threat Model (16%)

    Updated 25 Aug 2026

  5. Hands-on Lab 16 min Paid

    Attacker Persistence Mechanisms

    A cluster-admin binding, a token with no expiry, and a beacon that is not a running process.

    Domain 4 - Kubernetes Threat Model (16%)

    Updated 25 Aug 2026

  6. Hands-on Lab 18 min Paid

    Denial of Service and Resource Controls

    A container with no ceiling at all, then one killed at exit 137 - and the three layers between them.

    Domain 4 - Kubernetes Threat Model (16%)

    Updated 25 Aug 2026

Platform Security6 guides

Image signing and scanning, admission control, policy before a workload runs. 16%.

  1. Hands-on Lab 18 min Paid

    Admission Control and ValidatingAdmissionPolicy

    27 plugins nobody enabled, and then a rule of your own that refuses a Pod - with nothing to install.

    Domain 5 - Platform Security (16%)

    Updated 25 Aug 2026

  2. Hands-on Lab 17 min Paid

    Image Tags, Digests and Pull Policy

    Every running container on this cluster is pinned to a digest. None of their manifests said so.

    Domain 5 - Platform Security (16%)

    Updated 25 Aug 2026

  3. Hands-on Lab 15 min Paid

    Private Registry Authentication

    A registry password in clear inside a Secret - and the one word in the error that tells you whether it was used.

    Domain 5 - Platform Security (16%)

    Updated 25 Aug 2026

  4. Hands-on Lab 20 min Paid

    Cluster PKI and Certificate Signing Requests

    Three certificate authorities, eleven private keys, and a CSR the cluster signs into a working login.

    Domain 5 - Platform Security (16%)

    Updated 25 Aug 2026

  5. Hands-on Lab 16 min Paid

    Network Flow Observability

    Every connection named by Pod, a DROPPED verdict that says which policy - and no payload anywhere in the record.

    Domain 5 - Platform Security (16%)

    Updated 25 Aug 2026

  6. Hands-on Lab 20 min Paid

    Service Mesh Security Capabilities

    A canary string read straight off the wire with tcpdump - then HTTP-level policy with no sidecar anywhere.

    Domain 5 - Platform Security (16%)

    Updated 25 Aug 2026

Compliance and Frameworks3 guides

CIS Benchmarks, threat frameworks, and what an auditor actually asks for. 10%.

  1. Hands-on Lab 18 min Paid

    CIS Benchmark Assessment with kube-bench

    38 pass, 9 fail, 12 warn - and a policies section that scores nothing at all.

    Domain 6 - Compliance and Security Frameworks (10%)

    Updated 25 Aug 2026

  2. Hands-on Lab 16 min Paid

    Image Scanning and Supply Chain Checks

    798 findings in one base image and 0 in another, from the same scanner in the same minute.

    Domain 6 - Compliance and Security Frameworks (10%)

    Updated 25 Aug 2026

  3. Hands-on Lab 18 min Paid

    Threat Modeling with STRIDE

    Six letters, six commands, six answers - and every one of them is a finding.

    Domain 6 - Compliance and Security Frameworks (10%)

    Updated 25 Aug 2026

Working at Exam Speed2 guides

A multiple-choice security exam at 75% - where the marks are lost.

  1. Troubleshooting 16 min Paid

    Commonly Confused KCSA Concepts

    Six pairs that look identical on paper, each settled by one command on a real cluster.

    All six domains

    Updated 25 Aug 2026

  2. Concepts 14 min Paid

    KCSA Exam Timing and Error Budget

    90 seconds a question, 15 wrong allowed - and the arithmetic of which domains you can afford to lose.

    All six domains

    Updated 25 Aug 2026

Command Cheat Sheets1 sheet

Searchable references across the six domains.

← Back to Learn