Kubernetes CKS Study Roadmap
Last updated: March 30, 2026
Domain Weight Distribution
Week-by-Week Study Plan
Domain 1: Cluster Setup — CIS benchmarks, network policies, Ingress TLS, node security, GUI restrictions
Domain 2: Cluster Hardening — RBAC lockdown, service account security, restrict API access, upgrade cluster
Domain 2: System Hardening — AppArmor, Seccomp profiles, syscall filtering, minimize host OS footprint
Domain 3: System Hardening — Reduce attack surface, kernel hardening, disable unnecessary services
Domain 4: Microservices — SecurityContext, Pod Security Standards, OPA/Gatekeeper, Secrets management
Domain 4: Runtime Security — Container runtime sandboxing (gVisor/Kata), mTLS, service mesh security
Domain 5: Supply Chain — Image scanning (Trivy), ImagePolicyWebhook, allowlisting registries, signing
Domain 5: Static Analysis — Kubesec, kube-bench, OPA Conftest, manifest scanning, CI/CD security
Domain 6: Monitoring — Falco runtime detection, audit logging, immutable containers, filesystem monitoring
Full Review: Practice labs (killer.sh), CKS-specific scenarios, Weak areas, Exam logistics
Free Resources
Related Tools
Kubernetes CKS Study Guide
Complete exam objectives and domain breakdown
✅Study Tracker
Track objective completion with progress dashboard
💰Cost Calculator
Total cost breakdown and ROI analysis
🧪Practice Quiz
Test your knowledge with free practice questions
FixTheVuln Store
Get the Kubernetes CKS Study Planner
Fillable PDF with 10-week schedule, domain trackers, flashcard templates, and progress tracking.
Get the Study Planner — $5.99