CKS Exam Topics & Practice Tasks

Every task in the CKS lab maps to a domain in the official Certified Kubernetes Security Specialist curriculum. Below is the full list - what you'll practice, what each task tests, and how it maps to the exam blueprint.

16
graded tasks
6
CKS domains
120
min per attempt
Mapped
curriculum domains
Domain 1 10% of CKS exam

Cluster Setup

Lock down network access, the kubelet, API authentication, and ingress TLS, and run CIS benchmark checks.

Fix all issues via configuration and restart the affected components to ensure the new settings take effect. Fix all of the following violations that were found against the kubelet: The cluster uses the Docker Engine as its…

docs · k8s.io/docs/reference/access-authn-authz/kubelet-authn-authz
Domain 2 15% of CKS exam

Cluster Hardening

Restrict RBAC and service accounts, tighten API server flags, and keep the cluster patched.

Create a TLS Secret named clever-cactus in the clever-cactus namespace for an existing Deployment named clever-cactus. Use the following SSL files: Certificate: /home/candidate/clever-cactus/web.k8s.local.crt Key:…

docs · k8s.io/docs/concepts/configuration/secret
Domain 3 15% of CKS exam

System Hardening

Reduce the host attack surface with AppArmor, seccomp, and kernel hardening.

Domain 4 20% of CKS exam

Minimize Microservice Vulnerabilities

Apply Pod Security Standards, securityContext, and mTLS, and protect secrets at rest.

Modify the existing Deployment named lamp-deployment, running in namespace lamp, so that its containers: run with user ID 20000 use a read-only root filesystem forbid privilege escalation The Deployment's manifest file can be…

docs · k8s.io/docs/tasks/configure-pod-container/security-context
Domain 5 20% of CKS exam

Supply Chain Security

Scan images for vulnerabilities, harden Dockerfiles, generate SBOMs, and enforce image policy.

Given an incomplete configuration located at /etc/kubernetes/bouncer and a functional container image scanner with an HTTPS endpoint at https://smooth-yak.local/review, perform the following tasks to implement a validating…

docs · k8s.io/docs/reference/access-authn-authz/admission-controllers
Domain 6 20% of CKS exam

Monitoring, Logging and Runtime Security

Detect threats at runtime with Falco, behavioral analytics, and audit logging.

One of the Pods belonging to the application ollama is misbehaving. It is directly accessing the system's memory reading from the sensitive file /dev/mem. First, identify the misbehaving Pod accessing /dev/mem.

docs · falco.org/docs/concepts/rules

CKS access, clearly explained

$39 USD · 30 days · one payment. 16 graded tasks, 5 attempts at the full exam simulation and unlimited single-task practice during the access window. The clock starts when you activate.

Public task descriptions; the selected weekly lab is free with an account. 2 free weekly starts per certification. Read this week's free task →

List price before any applicable checkout taxes or discounts. Create an account →