CNCF / Associate / KCSA
Kubernetes and Cloud Security Associate
Recognize cloud native threats, select the right Kubernetes security control and explain the boundaries each control actually protects.
Reviewed 10 October 2026 against the current unversioned curriculum. The Linux Foundation scope explicitly includes authorization, which is omitted from the PDF bullet list; this guide covers both. CNCF also uses the expanded name Kubernetes and Cloud Native Security Associate. Curriculum attribution: CNCF, CC BY 4.0; explanations and questions are original. Check candidate instructions for current exam policies. Objective IDs are local navigation labels, not official codes.
THE REVISION PATH
Your topics, in order.
Read. Recall. Explain the alternative.
Security Layers and Shared Responsibility
Cloud contains cluster; cluster contains containers; containers execute code.
Images, Registries and the Software Supply Chain
Inventory tells what; provenance tells how; signatures tell who; scanning finds known risk.
Control Plane, Etcd and Client Trust
The API admits; controllers reconcile; the scheduler places; etcd remembers.
Node, Runtime, Pod and Storage Boundaries
The node owns the kernel; the Pod shares a network; access to either changes the blast radius.
Identity, RBAC, Secrets and Audit Evidence
Authenticate who, authorize what, protect the secret, record the request.
Pod Standards, Admission and Network Segmentation
Admission decides what enters; runtime settings constrain it; network policy limits where it talks.
Threat Modeling and Attack Paths
Draw the boundary, follow the identity, then limit persistence and movement.
Observability, PKI and Secure Connectivity
Observe the action, authenticate the peer and authorize the connection.
Compliance, Frameworks and Automated Evidence
A framework sets direction; a benchmark checks configuration; evidence proves the control ran.
How this guide is organised
Original revision explanations and scenario questions mapped to the public CNCF curriculum and Linux Foundation scope. Local objective IDs number the published subskills for navigation; they are not vendor-issued objective codes.
- Published CNCF KCSA curriculum ↗ Scope authority
- Linux Foundation KCSA exam and competencies ↗ Scope authority
- CNCF KCSA certification ↗ Exam and training
- Kubernetes security documentation ↗ Technical reference
Revision material supports preparation; it does not guarantee every possible exam question. Check the exam version and official objectives before booking.