CKS
The CKS is CNCF's hands-on, performance-based exam for engineers who secure Kubernetes clusters in production. There are no multiple-choice questions — you work inside live clusters from a Linux terminal and have two hours to harden nodes, write NetworkPolicies, configure admission controllers, and audit running workloads against real attacks. It's one of the few credentials that proves you can actually do the work, which is exactly why a misread task or a clock that runs out can cost you the attempt and the $445 sitting fee. This page breaks down what's tested, how it's delivered, and how to get it done right.
Pay Only After You Pass
No upfront fee — you settle only after your verified passing result. We advertise guaranteed results — 100% pass guaranteed or money back.
How the CKS is built — at a glance
120
A single 2-hour block to complete every task. The clock does not stop, so triage and time management decide as much as technical skill.
15–20
Each task carries a point weight shown on screen. You jump between several real Kubernetes clusters from a browser-based terminal — no multiple choice anywhere.
67%
Partial credit is awarded per task. Reach 67% of total points and you pass — there is no curve and no scaled rescore.
You operate inside a remote Linux desktop with a real kubectl and multiple clusters. Tasks tell you which cluster context to switch to first, then ask you to apply real fixes — patch a kubelet, write a NetworkPolicy, enable an admission controller, or scan an image. The grader checks the resulting cluster state, so the work has to actually function, not just look correct.
You may keep one extra browser tab open to the official Kubernetes documentation, plus a short allow-list of project sites (Falco, Trivy, AppArmor, etcd, and a few others). It's a helpful safety net for YAML syntax, but with only 120 minutes, candidates who lean on search instead of muscle memory tend to run out of time before they run out of tasks.
Six security domains — bars show each domain's official share of the exam
Network policies, CIS Benchmark checks with kube-bench, securing ingress with TLS, protecting node metadata and the GUI, and verifying platform binaries.
RBAC least privilege, restricting and rotating service-account tokens, locking down the API server, and keeping Kubernetes patched against known CVEs.
Reducing the host attack surface, AppArmor and seccomp profiles, kernel hardening, and minimizing IAM and external access from the node.
Pod Security Standards and admission control, OPA/Gatekeeper policies, managing secrets, container sandboxing with gVisor/Kata, and mTLS between services.
Minimizing base-image footprint, scanning images with Trivy, image allow-lists and admission gating, signing and validating artifacts, and SBOM/static analysis of workloads.
Behavioral analytics and threat detection with Falco, immutable containers at runtime, and configuring Kubernetes audit logging to investigate events.
The three 20% domains — microservice vulnerabilities, supply chain, and runtime security — together make up 60% of the exam, so they are where most of your points (and most of your prep time) should go. The official curriculum tracks a recent Kubernetes minor version and is updated within roughly 4–8 weeks of each new release, so always confirm you're studying the current version.
Taken online and watched live — what to expect on test day
The CKS runs entirely online through the PSI Secure Browser. You schedule a slot, launch the secure browser, pass identity and environment checks, then work inside a remote terminal that connects to the live exam clusters. There is no test-center option — everything happens from your own machine under a live proctor.
Registration includes two attempts at the Killer.sh exam simulator. Each session mirrors the real interface and runs harder than the actual exam, which makes it the single best gauge of whether you're ready. Treat both sessions as full dress rehearsals under the clock, not as a question bank to memorize.
A valid, unexpired government photo ID with a name matching your registration. The proctor captures your photo and verifies it before the exam unlocks.
A clear desk, a 360° webcam room scan, no second monitor, no phone or notes within reach, and no one else in the room for the full two hours.
Stay on camera the whole time. Only the exam terminal and the single allowed documentation tab may be open; leaving frame, talking aloud, or extra tabs can flag the session.
CKS is built for engineers who already run Kubernetes
CKA is mandatory — and the bar is high
Difficulty: CKS is widely considered the hardest of the three core Kubernetes exams. Two hours is genuinely tight for 15–20 weighted, multi-step tasks, and many candidates know the concepts but lose points to slow execution, context-switching mistakes, or fixes that don't actually take effect in the cluster. That execution pressure — not the theory — is exactly what our help is designed to remove.
CKS is a fast, unforgiving, hands-on exam where execution under the clock decides everything. Exam Assist pairs you with a vetted Kubernetes security specialist and works on a pay-after-you-pass model — so the risk sits with us, not you. No upfront fee, guaranteed results: just an honest feasibility answer and a verified result before you settle.
Tell us your CKA status, target test date, Kubernetes version, and where you stand on the six domains. Takes a couple of minutes over WhatsApp, Telegram, or Discord.
We review your timeline and readiness and tell you plainly whether it's realistic — before any money is discussed. If it isn't a fit, we say so.
Exam Assist handles the sitting end to end. You're matched with a CKS specialist who maps the work around the high-weight domains, the PSI environment, and the two-hour clock — discreetly and confidentially.
You only pay once your passing result is confirmed on your official CNCF report. No verified result, nothing owed.
Share your details and get a straight feasibility answer — pay only after a verified result.
Straight answers about the CKS exam
Book your help and compare sibling Kubernetes exams
Pair with a vetted Kubernetes security specialist on a results-first arrangement. No upfront fee — settle only after a verified passing result.
Book your help CKAThe required prerequisite for CKS — CNCF's hands-on exam for cluster administration, troubleshooting, and workloads.
View exam CKADCNCF's hands-on developer exam focused on building, deploying, and configuring cloud-native applications on Kubernetes.
View exam PCSEA related cloud-security credential — Google's exam for designing and operating secure infrastructure on Google Cloud.
View examGet expert CKS help with no upfront fee — you settle only after your verified passing result. Honest feasibility answer first, results-first arrangement always.