Red Hat Certified System Administrator Guide
·11 min read
What the RHCSA is, how the hands-on EX200 exam works, what it costs, how scoring and renewal work, and where it fits in Red Hat's 2026 certification tracks.
Continue readingWhat the Certified Kubernetes Security Specialist exam covers, its CKA prerequisite, six domains, cost, format and how to know when you are ready.

The Certified Kubernetes Security Specialist (CKS) is the Cloud Native Computing Foundation's advanced, hands-on credential for securing Kubernetes clusters and the workloads running on them. It is administered by The Linux Foundation, costs $445 USD as of 2026, runs for two hours in a live cluster environment, and — uniquely among CNCF certifications — requires you to already hold a current Certified Kubernetes Administrator (CKA) certification before you can sit it.
That prerequisite tells you most of what you need to know about the exam's positioning. CKS is not where you learn Kubernetes; it is where you prove you can defend it. This guide walks through the certification end to end: what it validates, the CKA gate, all six exam domains and what each really demands, the format and logistics, pricing options, and how to judge whether you are ready to book it.
CKS confirms that a certified Kubernetes administrator can secure container-based applications and Kubernetes platforms across their whole lifecycle — during build, deployment and runtime. The exam is performance-based: you work at a command line inside real clusters, completing security tasks under time pressure rather than answering multiple-choice questions. As of August 2026 the exam environment is based on Kubernetes v1.35, and the Linux Foundation updates it to the newest minor version within four to eight weeks of each Kubernetes release.
In practical terms, the certification maps to the day-to-day work of platform security. Employers reading "CKS" on a CV can reasonably expect the holder to harden a cluster's control plane, restrict workload permissions, lock down the software supply chain and detect suspicious behaviour at runtime — all demonstrated live, not merely recalled.
Because CNCF's performance-based exams put candidates in front of genuine clusters, they carry more hiring weight than most multiple-choice credentials. That applies doubly to CKS, which sits at the top of the CNCF Kubernetes ladder. If you want the wider map of that ladder before committing to its summit, our overview of Kubernetes certifications explained covers all five CNCF credentials and who each one serves.
You must hold a current, non-expired CKA before attempting the CKS. This is enforced, not advisory. There are three consequences worth planning around.
First, your sequencing is fixed. However strong your security background, the route to CKS runs through cluster administration. If you have not yet earned the CKA, start with the Certified Kubernetes Administrator guide to understand that exam's format, domains and registration process.
Second, expiry matters. CNCF certifications earned on or after 1 April 2024 are valid for two years (earlier certifications kept their original three-year validity). If your CKA lapses before you sit the CKS, you will need to re-earn it first. Candidates who intend to add CKS should check their CKA expiry date before purchasing, because the CKS purchase itself comes with a twelve-month eligibility window — you want both clocks to line up.
Third, KCSA is not a substitute. The Kubernetes and Cloud Native Security Associate (KCSA) is CNCF's entry-level, multiple-choice security credential. It can be a useful conceptual warm-up, but it does not satisfy the CKS prerequisite; only the CKA does. If you are earlier in your security journey, the KCSA exam page is a gentler on-ramp to the same subject matter.
Whether the security specialisation is worth adding on top of your CKA — and when in your career the investment pays off — is a separate question, answered in our comparison of CKA vs CKS.
As of 2026 the Linux Foundation lists six domains. The weights below come from the official certification page; always confirm the live curriculum before you book, since CNCF revises its exams periodically.
This domain concerns the workloads themselves: constraining what containers may do and how they may interact. Expect tasks around pod-level security settings, secrets management and isolating workloads from one another. The examiners are testing whether you can take an over-permissive deployment and reduce its blast radius without breaking the application.
Modern attacks increasingly enter through the build pipeline rather than the running cluster. This domain covers trusting what you deploy: minimising base image footprints, validating and restricting image sources, and scanning artefacts for known weaknesses before they reach production. It rewards candidates who think of security as starting before kubectl apply.
Prevention fails eventually, so detection matters. Here you demonstrate behavioural analytics at the syscall and process level, detecting anomalous activity inside containers, ensuring container immutability, and using audit logs to reconstruct what happened. Runtime tooling tasks in this domain tend to punish candidates who have only read about the tools rather than run them.
This domain covers the security posture you establish when a cluster is born: network policies that restrict pod-to-pod traffic, securing node metadata and endpoints, verifying platform binaries, and reviewing cluster components against security benchmarks. It overlaps most directly with knowledge you built for the CKA, extended with a defensive mindset.
Where Cluster Setup is about initial posture, hardening is about tightening a live cluster: restricting access to the Kubernetes API, configuring role-based access control to grant the minimum necessary privilege, managing service accounts carefully, and keeping the cluster version current. RBAC tasks here can be fiddly under time pressure, so fluency counts.
The smallest domain reaches below Kubernetes to the host: minimising the operating system footprint, reducing identity and access management exposure, closing unneeded ports and restricting kernel-level behaviour. Candidates from a pure development background often find this the least familiar territory, because it is classic Linux systems administration wearing a security hat.
Three domains — microservice vulnerabilities, supply chain, and runtime security — account for 60% of the exam between them, and they are also the areas least covered by CKA preparation. A sensible study plan therefore inverts many candidates' instincts: spend the majority of your time on the security-specific tooling and workflows you have not used before, and treat the cluster setup and hardening domains as extensions of ground you already hold.
The essentials, as of 2026:
The Linux Foundation does not publish an official pass rate for the CKS, and any figure you see quoted elsewhere is unofficial. The exam's reputation for difficulty rests instead on its structure: a broad six-domain syllabus, unfamiliar tooling, and a two-hour clock that punishes hesitation.
During the exam, performance-based CNCF certifications permit access to specified official documentation inside the exam environment. Check the current candidate handbook for the exact allowed-resources rule before exam day rather than relying on second-hand lists, as the policy details are defined there.
As of 2026, the Linux Foundation lists three purchase options:
Candidates planning the full professional track can buy the CKA + CKAD + CKS bundle at $1,245 USD — against $1,335 if bought separately — with one retake per exam, simulator access and the twelve-month window on each. The Linux Foundation also runs frequent sitewide sales, so if your timeline is flexible it is worth watching for a promotion rather than paying list price. Confirm current figures on the official certification page before purchasing, as pricing changes.
Remember to price in the prerequisite: if you do not yet hold a current CKA, the true cost of reaching CKS includes that exam too.
A CKS earned today is valid for two years. Renewal means retaking and passing the then-current exam — there is no continuing-education renewal path for CNCF certifications. Given that the exam tracks Kubernetes releases closely, a renewal attempt two years on will test a meaningfully evolved platform, which is arguably the point: the credential certifies current competence, not historical achievement.
The certification fits best when security responsibility is already, or is about to become, part of your role. Consider these three profiles.
The platform engineer inheriting security duties. An engineer who has run production clusters for two years and holds a CKA is asked to lead the team's security review after a compliance audit. For them, CKS preparation doubles as a structured curriculum for the actual job, and the credential documents the capability to auditors and leadership alike. This is the exam's centre of gravity.
The security professional moving into cloud native. Someone from a traditional security background has the defensive mindset but not the cluster fluency. Their gap is the prerequisite itself: earning the CKA first will be the larger project, and they should plan the two exams as one campaign rather than treating CKS as a quick add-on.
The developer curious about security. A developer without cluster administration experience and without a CKA is two steps away, not one. For this profile, the KCSA's multiple-choice format offers a lower-stakes way to test interest in the field before committing to the CKA-then-CKS route.
Who should wait? Anyone whose CKA has expired (renew first), anyone who has never operated the security tooling in the runtime and supply-chain domains (build lab time first), and anyone chasing the credential purely for salary reasons without security work on the horizon — a certification unsupported by practice fades quickly.
You are likely ready to schedule the CKS when you can honestly tick every box below:
Timed rehearsal deserves emphasis. The CKS clock is unforgiving, and the difference between knowing a task and finishing it in four minutes is precisely what the exam measures. Working through CKS practice questions domain by domain will show you which of the six areas need another pass before exam day — analyse your misses by domain and weight your remaining study accordingly, rather than revising evenly across material you have already secured.
No. The only prerequisite is a current CKA. The KCSA is an optional, entry-level, multiple-choice security credential that some candidates use to build conceptual grounding, but it grants no exam eligibility and skipping it costs you nothing formally.
Your purchase includes one free retake, which must be used within the twelve-month eligibility window that started when you bought the exam. Many candidates treat the first sitting as a calibration exercise; with a free retake in hand, an early attempt carries less financial risk than it might appear.
The Linux Foundation does not publish the task count for the live exam. The bundled killer.sh simulator presents 17 questions per session, but that figure describes the simulator, not the real exam.
Each certification carries its own two-year validity from its own earn date, so the clocks run independently. Holding a CKS does not extend your CKA; plan renewals separately.
The CKS is the most specialised of the CNCF Kubernetes certifications and the only one with an entry gate. That gate is a feature: it guarantees every CKS holder can administer the platform they are securing, which is why the credential reads as a genuine seniority signal rather than a badge. If you hold a current CKA, work with — or want to work with — cluster security, and can commit to serious lab time across the six domains, it is a coherent next step. If you are still deciding between deepening your administration skills and branching into security, settle that question first with the CKA vs CKS comparison, then come back to this guide when the decision is made.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
What the RHCSA is, how the hands-on EX200 exam works, what it costs, how scoring and renewal work, and where it fits in Red Hat's 2026 certification tracks.
Continue reading·11 min read
What the RHCE credential is in 2026: the Ansible-based EX294 exam, prerequisites, cost, renewal rules and the retitling under Red Hat's new track system.
Continue reading·7 min read
An honest look at RHCSA difficulty: why the hands-on EX200 format fails people who could pass on paper, who struggles most, and how failure actually works.
Continue reading