KCSA Preparation
Workshop

The KCSA exam (Kubernetes and Cloud Native Security Associate) covers six domains: from the 4Cs of Cloud Native Security to cluster components, security fundamentals, threat modeling, platform security, and compliance. 60 multiple-choice questions in 90 minutes, 75% to pass. Sounds manageable, but the breadth of topics catches many candidates off guard. On day one, you build the foundation: the 4C security model, image security with Trivy, and securing all control plane and node components. You will understand why etcd encryption is not optional and which Kubelet flags make a difference. On da

Made in Germany ISO 27001 ISO 9001 DSGVO-konform DORA Compliant 24/7 Support
UDSVolkswagenLiebherrT-SystemsVendureecoConnextPortainerBITMARCKUelzener VersicherungenFJDDWTOCCReiner SCTCyrus IndustrialDGSIEMnanocosmosInheadenSplixSchwarzgruppeINHHadesHiOrg-Serverown3dTikfinityProgram51Buben & MädchenPrime InsightsTELTECElevantiqMoovitCFToolsStadt KölnVivavisAvemio

Workshop overview

Duration, per-participant price and logistics for KCSA Preparation.

On-site options

  • Live online or on-site at your location

  • In-house: content, duration and focus can be tailored

  • Flexible dates, from 1 participant

  • German; English on request

  • Preconfigured cloud lab (also on-site)

  • Open groups: max. 8 people

  • Seat price same as online: €721.50 × days, excl. VAT

  • On-site in-house: individual quote (travel/logistics as incurred)

  • No published flat on-site surcharge

  • You provide the training room and internet

  • Open sessions: 09:00–16:00 (CET/CEST)

Curriculum

Topics by day at a glance.

Day 1: Understand Cloud Native Security and secure Kubernetes cluster components

  • The 4Cs of Cloud Native Security
  • Image Security and Artifact Repositories
  • Control Plane Security: API Server, etcd and Scheduler
  • Node Security: Kubelet, Container Runtime and KubeProxy
  • Container Networking, Storage and Client Security
Day 1

Day 2: Configure security fundamentals and analyze threat models

  • Pod Security Standards and Pod Security Admissions
  • Authentication and Authorization with RBAC
  • Secrets Management, Namespace Isolation and Audit Logging
  • Writing and Testing Network Policies
  • Kubernetes Threat Model: Attack Vectors and Mitigations
Day 2

Day 3: Implement platform security, verify compliance and prepare for the exam

  • Runtime Security with Falco
  • Policy Enforcement with OPA Gatekeeper and Admission Control
  • Supply Chain Security, PKI and Service Mesh
  • Compliance Frameworks and Security Tooling
  • KCSA Exam Preparation: Format, Strategy and Sample Questions
Day 3

Workshop schedule

Published daily rhythm. Topics are listed in the curriculum.

09:00–16:00 (CET/CEST)

Official window for open sessions.

Frame

09:00 – Introductions

On day 1: meet the instructor and participants, plus the agenda and workshop structure.

Day 1

09:00 – Q&A

On later days, resolve open questions from the previous day before the day’s topics (usually 09:00–09:30 or 09:00–10:00).

Later days

Content blocks follow the curriculum

Theory and hands-on in the morning and afternoon blocks. The topic list is in the curriculum above.

Topics

12:00–13:00 – Lunch

A shared break before the afternoon.

Break

16:00–16:30 – Q&A

End of the day: questions, exchange and wrap-up.

Close

Prerequisites

What participants should bring.

Hardware

Your own notebook (Linux, macOS or Windows) with permission to install software. Devices available at extra cost.

HardwareNotebook

Environment

Each participant works in a provided cloud lab. Local installation of the training stack is not required.

LabCloud

Prerequisites

Basic Linux/terminal skills are helpful.

Prerequisites

Related workshops

Suggested follow-on courses from the catalog.