Kubernetes and Cloud Native Security Associate

CNCF / Linux Foundation · KCSA · Associate

CNCF / Linux Foundation · CNCF Ecosystem

Kubernetes and Cloud Native Security Associate

KCSAactiveAssociate
Official CNCF / Linux Foundation source · cncf.io

KCSA · ● Active · Associate · CNCF / Linux Foundation


Exam facts

FieldValue
Cost$250 USD (includes one free retake)
Duration90 minutes
Questions60 multiple choice / multiple select
Passing75%
FormatOnline proctored, multiple choice / multiple select
DeliveryPSI Bridge (proctored)
LanguagesEnglish
Valid2 years
RenewalRetake; or automatic via CARE Program if you earn CKS after Jan 1, 2026
PrerequisitesNone
Released2024 (KubeCon EU)
RetiringN/A

Vendor source — CNCF Training & Certification ↗
Official exam guide — KCSA Certification (Linux Foundation) ↗
Exam objectives — KCSA Exam Domains ↗


About

The KCSA is a pre-professional (Associate-level) certification launched by CNCF in 2024 (KubeCon EU), designed for candidates seeking foundational knowledge and skills in cloud-native security technologies. It validates the ability to evaluate Kubernetes cluster security configurations, harden controls, test and monitor security, and assess vulnerabilities. Unlike hands-on professional certs (CKS, CKA), KCSA is a knowledge-based multiple-choice exam with no prerequisites — making it an ideal entry point for practitioners new to cloud-native security or transitioning from traditional infrastructure security. The exam sits between KCNA (foundational cloud-native concepts) and CKS (professional hands-on security specialist), forming a clear progression path for Kubestronaut seekers.


Domain context — Security

Container and Kubernetes cluster security: cloud-native threat models, cluster component hardening, RBAC, network policies, image security, secrets management, compliance frameworks, and security best practices for cloud-native applications and infrastructure.

Read full deep dive — CNCF Ecosystem ↗


Topics covered

  • Overview of Cloud Native Security (14%) — The 4Cs of Cloud Native Security (cloud, cluster, container, code); cloud provider security; infrastructure isolation; container and artifact security; workload and code security.
  • Kubernetes Cluster Component Security (22%) — API server, controller manager, scheduler, kubelet, container runtime, kube-proxy, pod, etcd, container networking, client security, storage security.
  • Kubernetes Security Fundamentals (22%) — RBAC (roles, role bindings, cluster roles), service accounts, pod security standards, network policies, secrets management, admission control.
  • Kubernetes Threat Model (16%) — Attack vectors, threat assessment, persistence techniques, common attack surfaces specific to Kubernetes environments.
  • Platform Security (16%) — Infrastructure and platform-level security controls, supply chain security (image signing, artifact verification, SBOM), runtime security (Falco, container escape detection), vulnerability management.
  • Compliance and Security Frameworks (10%) — Industry standards (CIS Benchmarks for Kubernetes), compliance requirements (SOC 2, PCI-DSS, NIST), security governance, audit logging.

Source: CNCF KCSA Exam Guide ↗ · Linux Foundation KCSA Certification ↗ · CNCF Curriculum Repository ↗


Common skills at Security · Associate

Shared content for the Security domain at Associate level — not specific to this cert.

  • Design and implement basic role-based access control (RBAC) policies
  • Secure containerized workloads across Kubernetes and container platforms
  • Evaluate and select appropriate authentication mechanisms
  • Implement network segmentation strategies (network policies)
  • Apply basic compliance and security frameworks (CIS Benchmarks)
  • Identify and assess common security vulnerabilities in containers and clusters
  • Implement basic audit logging and monitoring

Recommended courses at Security · Associate

ProviderTitleCostURL
Linux FoundationKubernetes Security Essentials (LFS260)$799 (includes exam voucher)
KodeKloudKCSA Certification Course (Mumshad Mannambeth)$99
A Cloud GuruKubernetes and Cloud Native Security Associate (KCSA)$49/month
Linux FoundationKCNA + KCSA Bundle$299
YouTubeKCSA Study Guides & Free ResourcesFreeDave Watts Medium ↗

Course-selection rule: LFS260 is the official Linux Foundation course for KCSA; KodeKloud offers structured, affordable prep. A Cloud Guru provides on-demand video training. The KCNA + KCSA bundle is cost-effective if you lack cloud-native fundamentals (KCNA covers general Kubernetes concepts). Free resources like community blogs are valuable supplements.


Practice exams

ProviderTitleCostURL
Linux FoundationKCSA Practice Exam (1 session, 90 min)Included with LFS260 or $99 standalone
KodeKloudMock Exams (included in course)Included
WhizlabsKCSA Practice Tests$49

Note: Unlike hands-on professional certs (CKS), KCSA has no killer.sh simulator — it is a knowledge-based exam with proctored multiple-choice questions. Preparation is conceptual rather than lab-focused.


Books

TitleAuthorPublisherYearISBNURL
Kubernetes Security and ObservabilityBrendan Creane, Amit GuptaO'Reilly2023978-1-098-12067-8

Book note: "Kubernetes Security and Observability" covers cloud-native security, container hardening, network policies, RBAC, secrets management, compliance, and observability — all core KCSA domains. While not KCSA-specific, it is the authoritative reference for foundational and professional-level Kubernetes security knowledge. Most KCSA prep relies on official exam curriculum PDF + online courses rather than a dedicated textbook.


Typical job titles at Security · Associate

Junior Kubernetes Security Engineer · Cloud Native Security Engineer · DevSecOps Engineer (entry) · Cloud Security Analyst · Container Security Engineer · Platform Security Engineer (junior) · Security Operations Engineer (Cloud-native)

(Job titles drawn from current job-board postings and LinkedIn that list KCSA as preferred or entry-point certification.)


Salary

Salary note: Cloud-native security is a premium skillset; roles with KCSA certification or advanced Kubernetes knowledge command 20–30% premium over generic cloud engineer roles. Data reflects 2026 market rates for mid-level roles (3–5 yrs experience in cloud/Kubernetes). KCSA alone typically supports junior-to-mid IC roles; combination with CKS or hands-on experience commands higher compensation. Security specialization adds $10,000–$25,000 to baseline cloud engineer salary.


Skills validated

Cert-specific — what this exam actually tests.

  • Evaluate the 4Cs of Cloud Native Security (Cloud, Cluster, Container, Code) and apply them to architecture design
  • Assess cloud provider security models and infrastructure isolation mechanisms
  • Identify and evaluate Kubernetes cluster component vulnerabilities (API server, etcd, kubelet, container runtime)
  • Design and interpret RBAC policies, role bindings, and service account configurations
  • Evaluate and implement Kubernetes network policies for workload isolation
  • Assess container image security: scanning tools (Trivy, Clair), image signing, registry security, private registries
  • Understand secrets management, encryption at rest, and external secret stores
  • Evaluate pod security standards and admission control mechanisms (ValidatingWebhooks, MutatingWebhooks, policy engines)
  • Identify common Kubernetes threat models and attack vectors (lateral movement, privilege escalation, persistence)
  • Apply compliance frameworks (CIS Benchmarks for Kubernetes, SOC 2, PCI-DSS, NIST) to security assessments
  • Interpret Kubernetes audit logs and understand security monitoring strategies
  • Understand supply-chain security: signed artifacts, Software Bill of Materials (SBOM), artifact verification
  • Evaluate runtime security approaches (Falco, container escape detection, system call tracing)

Related certifications


Sources


Last verified: 2026-05-02
Parent ecosystem: CNCF Ecosystem
Parent domain: Security
Vendor overview: CNCF Vendor Overview

Rate this cert
Was this helpful?
Comments ()
0/2000