Exam integrity: This independent roadmap contains original educational material based only on public objectives and official documentation. It does not reproduce, solicit, or claim access to live or recalled exam questions. PrepKloud is not affiliated with or endorsed by CNCF or the Linux Foundation. Verify current exam policies on the official pages before scheduling.
Verified exam snapshot — August 20, 2026
The official pages describe KCSA as an active online, proctored, multiple-choice exam lasting 90 minutes. It is positioned at the beginner / pre-professional level, and the credential is listed as valid for two years. The public blueprint allocates 14% to Overview of Cloud Native Security, 22% to Kubernetes Cluster Component Security, 22% to Kubernetes Security Fundamentals, 16% to Kubernetes Threat Model, 16% to Platform Security, and 10% to Compliance and Security Frameworks.
14%Overview of Cloud Native Security
22%Kubernetes Cluster Component Security
22%Kubernetes Security Fundamentals
16%Kubernetes Threat Model
16%Platform Security
10%Compliance and Security Frameworks
1
Cloud-native security foundations and the 4Cs
Week 1
Begin with security outcomes and shared responsibility rather than memorizing product names. Learn why cloud, cluster, container, and code controls overlap but do not replace one another.
- Draw Cloud, Cluster, Container, and Code layers for a simple application and assign owners
- Follow build, distribution, deployment, and runtime stages from the CNCF security lifecycle
- Compare process isolation with virtual-machine and sandbox boundaries without treating any boundary as absolute
- Map NIST SP 800-190 image, registry, orchestrator, container, host, and operational risks
- Explain preventive, detective, corrective, and recovery controls using one original scenario
- Separate a security framework from evidence that a particular control works
- Practice shared-responsibility decisions for self-managed and managed Kubernetes
2
Cluster components, clients, networking, and storage
Week 2
Learn what each component does, which credentials and data it handles, how it communicates, and what compromise could enable.
- Trace a request through kube-apiserver authentication, authorization, admission, persistence, and audit
- Explain etcd confidentiality, authenticated TLS, encryption at rest, backups, and key custody
- Distinguish scheduler placement from controller reconciliation and protect their API identities
- Harden kubelet access and understand Node authorization plus NodeRestriction
- Protect container runtime sockets and understand CRI as a privileged node boundary
- Explain kube-proxy, Service forwarding, CNI networking, DNS, and NetworkPolicy enforcement
- Treat kubeconfig files, client keys, storage classes, volumes, snapshots, and reclaim behavior as security assets
3
Pod Security, access control, Secrets, audit, and segmentation
Weeks 3–4
Turn architecture knowledge into practical control decisions. Test expected denials as carefully as expected successes.
- Compare Privileged, Baseline, and Restricted Pod Security Standards
- Use enforce, audit, and warn modes with pinned Pod Security Admission versions
- Apply non-root, no privilege escalation, RuntimeDefault seccomp, dropped capabilities, and constrained volumes
- Separate authentication, authorization, and admission; use namespace-scoped least-privilege RBAC
- Review transitive privilege through workload creation, bind, escalate, impersonate, token, CSR, webhook, and nodes/proxy access
- Disable unnecessary ServiceAccount token mounting and prefer short-lived, audience-bound tokens
- Protect Secrets at rest, in transit, in manifests, in mounts, in application memory, and in logs
- Apply default-deny ingress and egress with explicit DNS and required paths on an enforcing plugin
- Design ordered audit policy rules and monitor the audit backend for errors and loss
4
Threat model and platform security
Week 5
Connect cluster controls to realistic threats: persistence, denial of service, malicious execution, network interception, sensitive-data access, and privilege escalation.
- Inventory assets, actors, entry points, data flows, identities, trust boundaries, assumptions, and owners
- Model controller, admission, volume, credential, image, and node persistence beyond one Pod
- Use ResourceQuota and least privilege to reason about denial-of-service paths
- Correlate compromised application execution with reachable service accounts, networks, storage, and cloud authority
- Understand PKI identity, certificate purpose, trust roots, rotation, expiry, and key protection
- Explain how a service mesh may add authenticated service communication and telemetry while introducing new trust
- Build privacy-minimized observability and state when missing evidence makes coverage unknown
- Validate admission timeout, scope, failure policy, certificate, bypass, and recovery decisions
5
Supply chain, compliance evidence, and exam readiness
Week 6+
Finish by joining source, builder, artifact, admission, runtime, and governance evidence while preserving uncertainty and exam integrity.
- Build once and identify the artifact by digest instead of trusting mutable tags
- Distinguish SBOM inventory, vulnerability findings, signatures, and SLSA provenance
- Use Sigstore verification policy to constrain digest, identity, issuer, and required attestations
- Represent pass, fail, exception, unknown, stale, provider-managed, manual, and not-applicable evidence separately
- Automate evidence gathering without calling a dashboard an audit or compliance guarantee
- Complete all three synthetic projects with failure injection, security validation, cost, privacy, and cleanup
- Answer all 50 original questions and explain every rejected option from first principles
- Review the 40 flashcards with spaced repetition and revisit weak domains by official weight
- Read the current candidate handbook and official exam page before scheduling
Three evidence-driven projects
Secure cluster baseline
Assess every major component and validate Pod Security, RBAC, Secrets, networking, storage, audit, failure states, cost, and cleanup.
Open project details
Threat model and detection lab
Model trust boundaries, generate safe local behaviors, correlate audit and runtime evidence, contain with approval, recover, and tear down.
Open project details
Supply-chain evidence pipeline
Build by digest, create SBOM and SLSA provenance, sign with Sigstore, enforce admission, report evidence states, and revoke trust.
Open project details
Use every learning surface
50 original KCSA questions
Two sets of 25 with zero-based answers, detailed explanations, and an official reference for every question.
40 KCSA flashcards
Recall components, Pod Security, identity, networking, Secrets, threats, supply chain, and evidence.
3 synthetic projects
Practice architecture, denied paths, validation, failure injection, cost, and complete cleanup.
Complete KCSA guide
Read a long-form explanation of every domain and a six-week preparation method.
Cloud-native security roles
Explore roles while treating certification and projects as evidence, not employment guarantees.
Editorial policy
Review sourcing, independence, originality, corrections, and exam-integrity commitments.
Primary official references
Official KCSA certificationCurrent format, level, validity, domains, and exam resources.
Linux Foundation KCSA
CNCF Security WhitepaperBuild, distribution, deployment, and runtime security lifecycle.
CNCF whitepaper
Frequently asked questions
Is KCSA an active certification in 2026?
Yes. As checked on August 20, 2026, CNCF and Linux Foundation list KCSA as an active certification. Always use the official page for purchasing and policy decisions.
How long is the KCSA exam?
The official Linux Foundation page lists 90 minutes. Scheduling windows, attempts, system requirements, and candidate rules can change, so read the current handbook and important instructions.
Is KCSA beginner friendly?
It is positioned as beginner and pre-professional. That means conceptual breadth rather than no preparation: understand basic Kubernetes objects and architecture before focusing on security.
How long is KCSA certification valid?
The official product page states that KCSA is valid for two years. Consult official maintenance information as renewal programs can evolve.
Is KCSA a hands-on performance exam?
No. The official format is online, proctored, and multiple choice. Hands-on labs are still valuable because observed allowed and denied behavior makes conceptual distinctions memorable.
Are these practice questions real exam questions?
No. All 50 questions are original scenarios derived from public curriculum areas and official documentation. They are not recalled, leaked, or live exam content, and no score predicts an official result.
Independence and exam-integrity disclaimer: KCSA, Kubernetes, CNCF, and Linux Foundation names belong to their respective owners. PrepKloud is independent and not affiliated with or endorsed by those organizations. This roadmap does not reproduce protected exam material, guarantee a pass, certify compliance, or promise employment. Exam objectives, policies, software behavior, standards, and documentation change. Verify primary sources, use authorized disposable environments, protect evidence and credentials, and obtain professional review for production decisions.
Prepare from architecture to evidence
Use the weighted roadmap, test understanding with original scenarios, reinforce recall, and complete three safe projects.