Kubernetes and Cloud Native Security Associate (KCSA) Practice Test

140 questions available

Build your confidence for Kubernetes and Cloud Native Security Associate (KCSA). Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.

Try a sample question
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
Certification exam
60 Exam questions
1 hour 30 minutes Time Limit
Associate Level
Your practice
140 Practice questions
2 hours 20 minutes Practice Time
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
The bar to clear 75 Published passing score for this certification.
Explore exam topics Official objectives from CNCF
CNCF140 practice questions
Blueprint verifiedChecked against CNCF official objectivesMetadata verified 2026-06-11How we verify

Exam overview and details

The Kubernetes and Cloud Native Security Associate (KCSA) certification validates foundational expertise in securing containerized applications and Kubernetes environments. This vendor-neutral credential demonstrates a professional's ability to implement security best practices across the cloud-native stack, from cluster configuration and workload hardening to supply chain integrity and runtime defense. As organizations rapidly adopt Kubernetes, the demand for skilled professionals who can navigate its complex security landscape has become critical. Earning the KCSA signals to employers a verified, practical understanding of core security principles within the CNCF ecosystem, including network policy enforcement, secrets management, compliance monitoring, and vulnerability mitigation. This certification bridges the gap between theoretical security knowledge and the hands-on skills required to protect dynamic, distributed systems, making certified individuals invaluable assets in DevOps and platform engineering teams focused on building secure software supply chains.

Sample Questions

Choose an answer and explore the explanation to see how practice works.

Kubernetes Cluster Component Security

Which kubelet authentication+authorization combination is recommended for the authenticated kubelet API on port 10250?

Kubernetes Cluster Component Security

Which kubelet flag governs the rate at which kubelet rotates its own serving certificate?

Kubernetes Cluster Component Security

During CRI selection a team picks containerd. Which security feature should they verify is enabled in /etc/containerd/config.toml?

Kubernetes Security Fundamentals

Why is 'allowPrivilegeEscalation: true' a red flag in a PodSecurityContext?

Cloud Native Security Overview

What is the role of Rekor in the Sigstore architecture?

Career Opportunities & Salary

Median salary: $99,130– Network and Computer Systems Administrators

Source: BLS Occupational Employment and Wage Statistics, May 2025 -- Network and Computer Systems Administrators (SOC 15-1244), US national. Occupation median, not a certification salary. (2025)

Network and Computer Systems Administrators

Exam insights and study advice

In today's cloud-native landscape, security is not an afterthought but a foundational requirement. The KCSA certification provides industry-recognized validation of your skills, directly enhancing your professional credibility and marketability. It demonstrates a proactive commitment to mastering the security challenges inherent in container orchestration, a competency highly sought after by employers implementing or scaling Kubernetes. This credential can accelerate career advancement, open doors to roles such as Security Engineer, DevOps Engineer, and Cloud Architect, and often commands a premium in compensation. By aligning with the Cloud Native Computing Foundation's (CNCF) principles, the KCSA positions you at the forefront of industry standards, ensuring your skills remain relevant and in demand as the ecosystem evolves.

What this exam covers

Use the published domain weights to plan your study. Practice results do not predict your certification exam score.

01Kubernetes Cluster Component Security

22%

Topics

  • API Server
  • Controller Manager
  • Scheduler
  • Kubelet
  • Container Runtime
  • KubeProxy
  • Pod
  • Etcd
  • Container Networking
  • Client Security
  • Storage

Learning objectives

  • API Server
  • Controller Manager
  • Scheduler
  • Kubelet
  • Container Runtime
  • KubeProxy
  • Pod
  • Etcd
  • Container Networking
  • Client Security
  • Storage

02Kubernetes Security Fundamentals

22%

Topics

  • Pod Security Standards
  • Pod Security Admissions
  • Authentication
  • Authorization
  • Secrets
  • Isolation and Segmentation
  • Audit Logging
  • Network Policy

Learning objectives

  • Pod Security Standards
  • Pod Security Admissions
  • Authentication
  • Authorization
  • Secrets
  • Isolation and Segmentation
  • Audit Logging
  • Network Policy

03Kubernetes Threat Model

16%

Topics

  • Kubernetes Trust Boundaries and Data Flow
  • Persistence
  • Denial of Service
  • Malicious Code Execution and Compromised Applications in Containers
  • Attacker on the Network
  • Access to Sensitive Data
  • Privilege Escalation

Learning objectives

  • Kubernetes Trust Boundaries and Data Flow
  • Persistence
  • Denial of Service
  • Malicious Code Execution and Compromised Applications in Containers
  • Attacker on the Network
  • Access to Sensitive Data
  • Privilege Escalation

04Platform Security

16%

Topics

  • Supply Chain Security
  • Image Repository
  • Observability
  • Service Mesh
  • PKI
  • Connectivity
  • Admission Control

Learning objectives

  • Supply Chain Security
  • Image Repository
  • Observability
  • Service Mesh
  • PKI
  • Connectivity
  • Admission Control

05Overview of Cloud Native Security

14%

Topics

  • The 4Cs of Cloud Native Security
  • Cloud Provider and Infrastructure Security
  • Controls and Frameworks
  • Isolation Techniques
  • Artifact Repository and Image Security
  • Workload and Application Code Security

Learning objectives

  • The 4Cs of Cloud Native Security
  • Cloud Provider and Infrastructure Security
  • Controls and Frameworks
  • Isolation Techniques
  • Artifact Repository and Image Security
  • Workload and Application Code Security

06Compliance and Security Frameworks

10%

Topics

  • Compliance Frameworks
  • Threat Modelling Frameworks
  • Supply Chain Compliance

Learning objectives

  • Compliance Frameworks
  • Threat Modelling Frameworks
  • Supply Chain Compliance

Exam Details KCSA | $250 USD | 1 hour 30 minutes

Exam Code KCSA
Vendor CNCF
Exam Cost $250 USD
Passing Score 75
Time Limit 1 hour 30 minutes
Exam questions 60
Question Types Multiple choice (100%)
Retake Policy One free retake attempt is included with the exam purchase. A minimum 12-hour waiting period is required between attempts. The free retake must be used within 12 months of the original purchase.
Exam Format Performance-based (hands-on terminal)
Online Proctoring Available

Frequently Asked Questions

What are the prerequisites for taking the KCSA exam?

How does the KCSA differ from other Kubernetes security certifications?

What job roles is the KCSA certification most relevant for?

What is the typical format and duration of the KCSA exam?

How should I prepare for the KCSA exam?