Skip to content

KCSA Curriculum

Kubernetes and Cloud Native Security Associate - Entry-level certification for cloud native security fundamentals

The KCSA is a multiple-choice exam (not hands-on) that validates foundational knowledge of Kubernetes security and cloud native security concepts. It bridges the gap between general Kubernetes knowledge (KCNA/CKA) and specialist security skills (CKS).

AspectDetails
FormatMultiple choice
Duration90 minutes
Questions~60 questions
Passing Score75%
Validity3 years
PrerequisitesNone (CKA knowledge helpful)
PartTopicWeightModules
Part 0Introduction-2
Part 1Overview of Cloud Native Security14%3
Part 2Kubernetes Cluster Component Security22%4
Part 3Kubernetes Security Fundamentals22%5
Part 4Kubernetes Threat Model16%4
Part 5Platform Security16%4
Part 6Compliance and Security Frameworks10%3
Total100%25

Part 1: Overview of Cloud Native Security - 14% (3 modules)

Section titled “Part 1: Overview of Cloud Native Security - 14% (3 modules)”

Part 2: Kubernetes Cluster Component Security - 22% (4 modules)

Section titled “Part 2: Kubernetes Cluster Component Security - 22% (4 modules)”

Part 3: Kubernetes Security Fundamentals - 22% (5 modules)

Section titled “Part 3: Kubernetes Security Fundamentals - 22% (5 modules)”

Part 4: Kubernetes Threat Model - 16% (4 modules)

Section titled “Part 4: Kubernetes Threat Model - 16% (4 modules)”

Part 5: Platform Security - 16% (4 modules)

Section titled “Part 5: Platform Security - 16% (4 modules)”

Part 6: Compliance and Security Frameworks - 10% (3 modules)

Section titled “Part 6: Compliance and Security Frameworks - 10% (3 modules)”
  1. Follow the order - Modules build on security concepts progressively
  2. Think “defense in depth” - Layer security at every level
  3. Understand threats first - Know what you’re defending against
  4. Take quizzes - Each module has quiz questions
  5. Connect to CKS - This prepares you for hands-on security skills
AspectKCSAKCNACKS
FocusSecurity conceptsGeneral K8s conceptsSecurity implementation
FormatMultiple choiceMultiple choiceHands-on
DifficultyAssociateAssociateSpecialist
PrerequisitesNoneNoneActive CKA
  • Master the 4 Cs - Cloud, Cluster, Container, Code frame everything
  • Think like an attacker - Understand threats to defend against them
  • Know security principles - Defense in depth, least privilege, zero trust
  • Understand components - Know what each K8s component does and its risks
  • Focus on Part 2 & 3 - They’re 44% of the exam combined

KCSA is the conceptual foundation for CKS:

KCSA (Concepts) CKS (Implementation)
────────────── ────────────────────
"What is RBAC?" → "Configure RBAC for service X"
"Why use PSS?" → "Apply restricted PSS to namespace"
"What is Falco?" → "Write Falco rules for detection"

If you pass KCSA and CKA, you’re well-prepared to tackle CKS.

Begin with Part 0: Introduction to understand the exam format and security mindset, then proceed through each part in order.

Good luck on your KCSA journey!