CKS - Certified Kubernetes Security Specialist Practice Test

140 questions available

Build your confidence for CKS - Certified Kubernetes Security Specialist. Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.

Try a sample question
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
140 Practice questions
2 hours 20 minutes Practice Time
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
The bar to clear 67/percentage Published passing score for this certification.
Official objectives from CNCF
CNCF140 practice questionsBank updated 2026-07-24
Blueprint verifiedChecked against CNCF official objectivesMetadata verified 2026-03-18How we verify

Exam overview and details

CNCF Certified Kubernetes Security Specialist exam covering cluster hardening, network policies, runtime security, and supply chain security. Administered by CNCF as a performance-based (hands-on terminal) format exam. Key domains include Cluster Hardening, Cluster Setup and Hardening, Minimize Microservice Vulnerabilities and Monitoring, Logging and Runtime Security.

Sample Questions

Choose an answer and explore the explanation to see how practice works.

Cluster Hardening

Which command shows the bound ClusterRoles and Roles that any subject would gain from being a member of group 'developers'? Scenario constraint: Kubernetes 1.34, containerd runtime, current CKS curriculum domain 'Cluster Hardening', and only upstream Kubernetes behavior should be assumed.

Cluster Hardening

What is the PRIMARY security advantage of running a workload under the `runsc` (gVisor) RuntimeClass instead of runc? Scenario constraint: Kubernetes 1.34, containerd runtime, current CKS curriculum domain 'Cluster Hardening', and only upstream Kubernetes behavior should be assumed.

Cluster Hardening

In a kubeadm cluster, which directory contains the PKI material whose CA private key compromise would let an attacker mint cluster-admin credentials? Scenario constraint: Kubernetes 1.34, containerd runtime, current CKS curriculum domain 'Cluster Hardening', and only upstream Kubernetes behavior should be assumed.

Monitoring, Logging and Runtime Security

During a forensic investigation, an admin deletes the offending pod immediately to stop the attacker. What's the trade-off? Scenario constraint: Kubernetes 1.34, containerd runtime, current CKS curriculum domain 'Monitoring, Logging and Runtime Security', and only upstream Kubernetes behavior should be assumed.

Supply Chain Security

Which is the best practice when consuming third-party Helm charts? Scenario constraint: Kubernetes 1.34, containerd runtime, current CKS curriculum domain 'Supply Chain Security', and only upstream Kubernetes behavior should be assumed.

Career Opportunities & Salary

Median salary: $99,130– Network and Computer Systems Administrators

Source: BLS Occupational Employment and Wage Statistics, May 2025 -- Network and Computer Systems Administrators (SOC 15-1244), US national. Occupation median, not a certification salary. (2025)

Network and Computer Systems Administrators

Exam insights and study advice

In real-world production environments, a single misconfigured Kubernetes deployment, exposed secret, or unpatched node can lead to catastrophic data breaches, service disruptions, and compliance failures. The CKS matters because it equips you with the practical skills to directly prevent these incidents. It moves beyond theory to the actual commands and configurations needed to enforce pod security standards, scan images for vulnerabilities, define network policies, and audit cluster activity. This certification translates directly into the ability to build more resilient systems, protect sensitive data, and meet stringent regulatory requirements like SOC 2, GDPR, and HIPAA in Kubernetes deployments, thereby safeguarding both organizational assets and reputation.

These are the backgrounds the certifying body suggests. Check the vendor's own page for anything it formally requires.

What this exam covers

01Cluster Hardening

02Cluster Setup and Hardening

03Minimize Microservice Vulnerabilities

04Monitoring, Logging and Runtime Security

05Pod Security

06Runtime Security

07Supply Chain Security

08System Hardening

Exam Details CKS

Exam Code CKS
Vendor CNCF
Passing Score 67/percentage
Exam Format Performance-based (hands-on terminal)
Online Proctoring Available

Frequently Asked Questions

Is the CKA a strict prerequisite, and why?

How much hands-on experience is needed before attempting the CKS?

What is the biggest challenge during the exam itself?

Are there any recommended study resources?

How is the CKS different from other security certifications?