KCSA (Kubernetes and Cloud Native Security Associate)
Cloud native threat models, the 4C model and platform hardening.
42 published guides
34 of 42 guides need path access. Unlock KCSA path
42-guide Kubernetes and Cloud Native Security Associate learning path · 42 published · about 670 min of reading · 9 learning tracks · reviewed 25 August 2026
Orientation3 guides
What KCSA asks, the 75% threshold, and the cluster it is studied on.
-
Concepts 12 min
KCSA Exam Format and Domain Weights
Six domains, 60 questions, and a 75% pass mark that allows fifteen wrong answers in total.
All six domainsUpdated 25 Aug 2026
-
Concepts 10 min
KCSA in the Kubernetes Certification Path
The same subjects at three depths - counted across all three question pools rather than described.
All six domainsUpdated 25 Aug 2026
-
Hands-on Lab 16 min
The KCSA Practice Cluster and Its Defaults
A cluster rebuilt from scratch today - and the posture it starts in, measured rather than assumed.
All six domainsUpdated 25 Aug 2026
Cloud Native Security5 guides
The 4C model - Cloud, Cluster, Container, Code - and where each control lives. 14%.
-
Hands-on Lab 18 min
The 4C Cloud Native Security Model
Cloud, Cluster, Container, Code - four layers, four commands, and two answers you will not like.
Domain 1 - Overview of Cloud Native Security (14%)Updated 25 Aug 2026
-
Troubleshooting 12 min
Cluster DNS and Service Discovery
The same name, two tools, two answers - and why the one that fails is the one people reach for.
Domain 1 - Overview of Cloud Native Security (14%)Updated 25 Aug 2026
-
Hands-on Lab 14 min
Pod Security Admission Levels
One label on a namespace, and the same Pod spec stops being allowed.
Domain 1 - Overview of Cloud Native Security (14%)Updated 25 Aug 2026
-
Hands-on Lab 18 min
Hardening a Pod with securityContext
Five settings, each one demonstrated - including the one that does less than people think.
Domain 1 - Overview of Cloud Native Security (14%)Updated 25 Aug 2026
-
Hands-on Lab 14 min
NetworkPolicy Default Deny and DNS
Seven lines of YAML, and the Pod can no longer resolve a name - which is the part people are not expecting.
Domain 1 - Overview of Cloud Native Security (14%)Updated 25 Aug 2026
Cluster Component Security9 guides
apiserver, etcd, kubelet, scheduler and controller-manager, one attack surface at a time. 22%.
-
Hands-on Lab 14 min Paid
Control Plane Static Pod Manifests
Static Pod manifests on one node, owned by nothing, started by the kubelet before the apiserver exists.
Domain 2 - Kubernetes Cluster Component Security (22%)Updated 25 Aug 2026
-
Hands-on Lab 16 min Paid
kube-apiserver Security Flags
Six flags, and the one that matters most is the one that is not there.
Domain 2 - Kubernetes Cluster Component Security (22%)Updated 25 Aug 2026
-
Hands-on Lab 18 min Paid
etcd Security and Access Control
A Secret read out of the datastore in plaintext, and the one flag that would have stopped it.
Domain 2 - Kubernetes Cluster Component Security (22%)Updated 25 Aug 2026
-
Hands-on Lab 16 min Paid
Kubelet API Access and Ports
Port 10250 with its own authentication, its own authorization, and a read-only port you should check is closed.
Domain 2 - Kubernetes Cluster Component Security (22%)Updated 25 Aug 2026
-
Hands-on Lab 16 min Paid
Node Authorization and NodeRestriction
One certificate, one year, and a permission list that is deliberately misleading.
Domain 2 - Kubernetes Cluster Component Security (22%)Updated 25 Aug 2026
-
Hands-on Lab 14 min Paid
Container Runtime Security
A socket that starts containers without asking Kubernetes, and 27 containers the apiserver never mentions.
Domain 2 - Kubernetes Cluster Component Security (22%)Updated 25 Aug 2026
-
Hands-on Lab 14 min Paid
kube-proxy and Service Implementation
Privileged, host-networked, and a Service that turns out to be a chain of iptables rules.
Domain 2 - Kubernetes Cluster Component Security (22%)Updated 25 Aug 2026
-
Hands-on Lab 16 min Paid
kubeconfig Files and Client Certificates
Five kubeconfigs on one node, and the second admin file most people do not know exists.
Domain 2 - Kubernetes Cluster Component Security (22%)Updated 25 Aug 2026
-
Hands-on Lab 17 min Paid
Storage Security: StorageClass, PV and CSI
Delete the claim, and read the data off the node afterwards.
Domain 2 - Kubernetes Cluster Component Security (22%)Updated 25 Aug 2026
Security Fundamentals8 guides
RBAC, Pod Security Admission, NetworkPolicy, Secrets and ServiceAccounts. 22%.
-
Hands-on Lab 18 min Paid
RBAC Fundamentals
An identity that can do nothing, then exactly one thing - and four queries proving where the edges are.
Domain 3 - Kubernetes Security Fundamentals (22%)Updated 25 Aug 2026
-
Hands-on Lab 16 min Paid
Projected ServiceAccount Tokens
Audience-bound, time-limited, issued on request - and what a bearer token proves when you use one by hand.
Domain 3 - Kubernetes Security Fundamentals (22%)Updated 25 Aug 2026
-
Hands-on Lab 14 min Paid
Privilege Escalation Paths in RBAC
Three queries to run on any cluster you inherit - and the one binding to unauthenticated callers that is supposed to be there.
Domain 3 - Kubernetes Security Fundamentals (22%)Updated 25 Aug 2026
-
Hands-on Lab 18 min Paid
Kubernetes Secrets and Exposure Paths
The same Secret as an environment variable and as a file - and only one of them shows up in /proc.
Domain 3 - Kubernetes Security Fundamentals (22%)Updated 25 Aug 2026
-
Hands-on Lab 18 min Paid
Pod Security Standards in Detail
Two Pod specs against three namespaces - and the exact line between baseline and restricted.
Domain 3 - Kubernetes Security Fundamentals (22%)Updated 25 Aug 2026
-
Hands-on Lab 12 min Paid
Namespaces as a Security Boundary
A Pod pinging across a namespace boundary while RBAC refuses the same crossing.
Domain 3 - Kubernetes Security Fundamentals (22%)Updated 25 Aug 2026
-
Hands-on Lab 14 min Paid
ResourceQuota and LimitRange as Security Controls
A quota that makes resource requests mandatory, and then refuses the third Pod.
Domain 3 - Kubernetes Security Fundamentals (22%)Updated 25 Aug 2026
-
Concepts 14 min Paid
Audit Logging and Cluster Records
Events that vanish after an hour, an operational log with no caller in it, and zero audit flags.
Domain 3 - Kubernetes Security Fundamentals (22%)Updated 25 Aug 2026
Kubernetes Threat Model6 guides
Thinking like the attacker: container escape, privilege escalation, lateral movement. 16%.
-
Hands-on Lab 16 min Paid
Trust Boundaries: Authentication and Authorization
The same request with a token and then without one - and the 403 that names each identity by hand.
Domain 4 - Kubernetes Threat Model (16%)Updated 25 Aug 2026
-
Hands-on Lab 15 min Paid
Network-Based Attack Vectors
A Pod in one namespace reads an internal service in another, then stops - after one NetworkPolicy.
Domain 4 - Kubernetes Threat Model (16%)Updated 25 Aug 2026
-
Hands-on Lab 18 min Paid
Compromised Container Blast Radius
Root in a container that cannot mount - and a token that reads the neighbouring team's Stripe key.
Domain 4 - Kubernetes Threat Model (16%)Updated 25 Aug 2026
-
Hands-on Lab 20 min Paid
Privilege Escalation from Pod to Node
A ServiceAccount that cannot read a Secret reads one anyway - off the node's disk.
Domain 4 - Kubernetes Threat Model (16%)Updated 25 Aug 2026
-
Hands-on Lab 16 min Paid
Attacker Persistence Mechanisms
A cluster-admin binding, a token with no expiry, and a beacon that is not a running process.
Domain 4 - Kubernetes Threat Model (16%)Updated 25 Aug 2026
-
Hands-on Lab 18 min Paid
Denial of Service and Resource Controls
A container with no ceiling at all, then one killed at exit 137 - and the three layers between them.
Domain 4 - Kubernetes Threat Model (16%)Updated 25 Aug 2026
Platform Security6 guides
Image signing and scanning, admission control, policy before a workload runs. 16%.
-
Hands-on Lab 18 min Paid
Admission Control and ValidatingAdmissionPolicy
27 plugins nobody enabled, and then a rule of your own that refuses a Pod - with nothing to install.
Domain 5 - Platform Security (16%)Updated 25 Aug 2026
-
Hands-on Lab 17 min Paid
Image Tags, Digests and Pull Policy
Every running container on this cluster is pinned to a digest. None of their manifests said so.
Domain 5 - Platform Security (16%)Updated 25 Aug 2026
-
Hands-on Lab 15 min Paid
Private Registry Authentication
A registry password in clear inside a Secret - and the one word in the error that tells you whether it was used.
Domain 5 - Platform Security (16%)Updated 25 Aug 2026
-
Hands-on Lab 20 min Paid
Cluster PKI and Certificate Signing Requests
Three certificate authorities, eleven private keys, and a CSR the cluster signs into a working login.
Domain 5 - Platform Security (16%)Updated 25 Aug 2026
-
Hands-on Lab 16 min Paid
Network Flow Observability
Every connection named by Pod, a DROPPED verdict that says which policy - and no payload anywhere in the record.
Domain 5 - Platform Security (16%)Updated 25 Aug 2026
-
Hands-on Lab 20 min Paid
Service Mesh Security Capabilities
A canary string read straight off the wire with tcpdump - then HTTP-level policy with no sidecar anywhere.
Domain 5 - Platform Security (16%)Updated 25 Aug 2026
Compliance and Frameworks3 guides
CIS Benchmarks, threat frameworks, and what an auditor actually asks for. 10%.
-
Hands-on Lab 18 min Paid
CIS Benchmark Assessment with kube-bench
38 pass, 9 fail, 12 warn - and a policies section that scores nothing at all.
Domain 6 - Compliance and Security Frameworks (10%)Updated 25 Aug 2026
-
Hands-on Lab 16 min Paid
Image Scanning and Supply Chain Checks
798 findings in one base image and 0 in another, from the same scanner in the same minute.
Domain 6 - Compliance and Security Frameworks (10%)Updated 25 Aug 2026
-
Hands-on Lab 18 min Paid
Threat Modeling with STRIDE
Six letters, six commands, six answers - and every one of them is a finding.
Domain 6 - Compliance and Security Frameworks (10%)Updated 25 Aug 2026
Working at Exam Speed2 guides
A multiple-choice security exam at 75% - where the marks are lost.
-
Troubleshooting 16 min Paid
Commonly Confused KCSA Concepts
Six pairs that look identical on paper, each settled by one command on a real cluster.
All six domainsUpdated 25 Aug 2026
-
Concepts 14 min Paid
KCSA Exam Timing and Error Budget
90 seconds a question, 15 wrong allowed - and the arithmetic of which domains you can afford to lose.
All six domainsUpdated 25 Aug 2026
Command Cheat Sheets1 sheet
Searchable references across the six domains.
-
Reference 12 min
KCSA security review cheat sheet
One command per security question, with the real answer underneath.
kubectl / kube-bench / trivyUpdated 25 Aug 2026