This is an example of a simple banner

Training: Certified Kubernetes Security Specialist (CKS) Preparation

Ref. KUB-14
Duration:
4
 jours
Exam:
Certifiant
Level:
Avancé

Certified Kubernetes Security Specialist (CKS) Preparation Training

The Certified Kubernetes Security Specialist (CKS) preparation course is aimed at professionals who want to validate advanced Kubernetes security skills. The CKS certification is a hands-on certification, oriented toward offensive and defensive security, covering in particular cluster hardening, supply chain security, runtime security, monitoring and incident response. The CKS is intended for already experienced practitioners and requires having obtained the CKA certification beforehand.

Advanced preparation for security, DevSecOps and platform profiles

This course is aimed at candidates who want to deepen the security of Kubernetes platforms in contexts close to production. It allows you to review the main syllabus domains, work on securing the deployment chain, strengthen workloads, monitor risky behaviors and prepare for the exam in realistic conditions.

Participant Profiles

  • DevSecOps engineers
  • Experienced Kubernetes administrators
  • Cloud security engineers
  • Platform architects
  • SREs or DevOps engineers with a security focus
  • Candidates preparing for the CKS certification

Objectives

  • Strengthen the security of a Kubernetes cluster
  • Secure workloads, configurations and the supply chain
  • Identify and address the most common vulnerabilities
  • Implement monitoring and detection mechanisms
  • Understand incident and remediation scenarios
  • Prepare in conditions consistent with the advanced expectations of the CKS exam

Prerequisites

  • Holding the CKA certification to be eligible to take the CKS exam
  • Having solid experience in Kubernetes administration
  • Mastery of kubectl, YAML, Linux and networking concepts
  • Prior experience in security or platform hardening is a significant advantage

Course Content

Module 1: Cluster setup and hardening

  • Cluster security
  • Attack surface reduction
  • Securing critical components
  • Hardening access and configurations
  • Basic best practices for securing the control plane and nodes

Module 2: Workload and container security

  • Security of Pods and containers
  • Security contexts
  • Permissions and privileges
  • Workload isolation
  • Security policies and best practices for secure deployment

Module 3: Supply chain security

  • Securing images and registries
  • Control of dependencies and artifacts
  • Validation and trust in the build chain
  • Reducing risks related to software supply
  • DevSecOps best practices applied to Kubernetes

Module 4: Monitoring, logging and detection

  • Monitoring abnormal behavior
  • Security logs and cluster events
  • Principles of incident detection
  • Visibility into workloads and platform
  • Security monitoring tooling at an operational level

Module 5: Incident response and remediation

  • Understanding incident scenarios in a Kubernetes environment
  • Responding to a compromise or suspicious behavior
  • Isolation, analysis and remediation
  • Corrective measures and return to a controlled state
  • Hands-on practical exercises

Module 6: Exam preparation

  • Review of the main certification domains
  • Timed practical exercises
  • Exam-style scenarios
  • Time management and prioritization
  • Final tips to succeed in the CKS

Documentation

  • Digital course materials included

Lab / Exercises

  • This course includes hands-on exercises designed to reinforce your knowledge and apply your skills in real-world professional scenarios.

Exam

  • This course prepares for the Certified Kubernetes Security Specialist (CKS) certification

Complementary Courses

Eligible Funding

ITTA is a partner of a continuing education fund dedicated to temporary workers. This fund can subsidize your training, provided that you are subject to the “Service Provision” collective labor agreement (CCT) and meet certain conditions, including having worked at least 88 hours in the past 12 months.

Additional Information

What is the CKS certification and why is it strategic?

The CKS (Certified Kubernetes Security Specialist) is the most advanced certification in the Kubernetes ecosystem, delivered by the CNCF and the Linux Foundation. It validates your expertise in securing Kubernetes clusters and containerized applications in production environments. The exam is 100% hands-on: for 2 hours, you must secure real clusters on the command line. Exam details are available on the Linux Foundation website.

Kubernetes security has become an absolute priority for organizations. Incidents related to misconfigured clusters, unverified images, or missing network policies are multiplying. In French-speaking Switzerland, where the banking, pharmaceutical, and watchmaking sectors handle sensitive data on containerized infrastructures, CKS-certified professionals are particularly sought after. This certification positions your expertise at the highest level of the Kubernetes competency chain.

CKS, KCSA, or both: which security path to choose?

The CNCF offers two security-oriented Kubernetes certifications, corresponding to different levels and formats:

KCSA

(Security Associate) – Intermediate multiple-choice certification. It covers cloud-native security fundamentals: the 4C model (Code, Container, Cluster, Cloud), RBAC, Network Policies, least privilege principles. No prerequisites.

  • CKS

    (Security Specialist) – Advanced entirely hands-on certification. It requires operational mastery of complete cluster security: system hardening, auditing, runtime security, supply chain. Mandatory prerequisite: holding the CKA.

  • For professionals discovering Kubernetes security, starting with the KCSA validates the fundamentals before tackling the CKS. For Kubernetes administrators already CKA-certified, the CKS is the natural next step to round out their profile with recognized security expertise.

    Key domains of the CKS exam

    The CKS exam covers six major domains reflecting real-world challenges of securing a production Kubernetes cluster. Secure cluster configuration includes CIS Benchmarks, component verification, and TLS certificate management. Cluster hardening covers advanced RBAC, Service Account restrictions, and limiting accessible APIs.

    System security covers reducing the attack surface on nodes, AppArmor/Seccomp profiles, and kernel hardening. Network security requires mastery of Network Policies, inter-pod encryption, and secure Ingress. Supply chain security covers image scanning, admission controllers (OPA/Gatekeeper), and provenance verification. Finally, monitoring and runtime detection cover audit logging, Falco, and behavioral analysis.

    Why the CKS requires guided training

    The CKS is considered the most difficult Kubernetes exam. The CKA prerequisite ensures a solid technical foundation, but the security domains covered are vast and specialized. Properly configuring an admission controller, writing Seccomp profiles, interpreting Falco alerts, or applying CIS Benchmarks requires guided practice on realistic environments.

    A 4-day intensive training allows you to work on each of these domains with an instructor who is an expert in Kubernetes security. You practice attack and remediation scenarios, develop security reflexes, and learn to prioritize actions under time constraints. This investment pays off quickly compared to the cost of a security incident in production.

    FAQ

    Is the CKA mandatory before taking the CKS?
    Yes, it is the only formal prerequisite imposed by the CNCF. Your CKA certification must be valid at the time of CKS registration.

    What is the CKS exam format?
    The exam is 100% hands-on, on the command line on real clusters. Details (duration, minimum score) are available on the official CNCF website.

    How long is the CKS certification valid?
    The CKS is valid for 2 years. It can be renewed by retaking the exam.

    Can documentation be used during the CKS exam?
    Yes, you have access to the official Kubernetes documentation and certain authorized resources during the exam.

    What is the Kubestronaut program?
    The CNCF Kubestronaut program rewards professionals who hold all five Kubernetes certifications (KCNA, CKAD, CKA, KCSA, CKS).

    Is the CKS harder than the CKA?
    Yes, it is generally considered the most demanding Kubernetes exam due to the diversity of security domains covered.

    Prix de l'inscription
    CHF 2'950.-
    Inclus dans ce cours
    • Training provided by an industry expert
    • Digital documentation and materials
    • Achievement badge
    Mois actuel

    lun06juil(juil 6)09:00jeu09(juil 9)17:00VirtuelVirtual Etiquettes de sessionKUB-14

    lun06juil(juil 6)09:00jeu09(juil 9)17:00Lausanne, Av. Mon-Repos 24, 1005 Lausanne Etiquettes de sessionKUB-14

    lun10Aoû(Aoû 10)09:00jeu13(Aoû 13)17:00VirtuelVirtual Etiquettes de sessionKUB-14

    lun10Aoû(Aoû 10)09:00jeu13(Aoû 13)17:00Genève, Route des Jeunes 35, 1227 Genève Etiquettes de sessionKUB-14

    lun14Sep(Sep 14)09:00jeu17(Sep 17)17:00VirtuelVirtual Etiquettes de sessionKUB-14

    lun14Sep(Sep 14)09:00jeu17(Sep 17)17:00Lausanne, Av. Mon-Repos 24, 1005 Lausanne Etiquettes de sessionKUB-14

    lun19Oct(Oct 19)09:00jeu22(Oct 22)17:00VirtuelVirtual Etiquettes de sessionKUB-14

    lun19Oct(Oct 19)09:00jeu22(Oct 22)17:00Genève, Route des Jeunes 35, 1227 Genève Etiquettes de sessionKUB-14

    lun23Nov(Nov 23)09:00jeu26(Nov 26)17:00VirtuelVirtual Etiquettes de sessionKUB-14

    lun23Nov(Nov 23)09:00jeu26(Nov 26)17:00Lausanne, Av. Mon-Repos 24, 1005 Lausanne Etiquettes de sessionKUB-14

    lun28Déc(Déc 28)09:00jeu31(Déc 31)17:00VirtuelVirtual Etiquettes de sessionKUB-14

    lun28Déc(Déc 28)09:00jeu31(Déc 31)17:00Genève, Route des Jeunes 35, 1227 Genève Etiquettes de sessionKUB-14

    Contact

    ITTA
    Route des jeunes 35
    1227 Carouge, Suisse

    Opening hours

    Monday to Friday
    8:30 AM to 6:00 PM
    Tel. 058 307 73 00

    Contact-us

    ITTA
    Route des jeunes 35
    1227 Carouge, Suisse

    Make a request

    Contact

    ITTA
    Route des jeunes 35
    1227 Carouge, Suisse

    Opening hours

    Monday to Friday, from 8:30 am to 06:00 pm.

    Contact us

    Your request