> For the complete documentation index, see [llms.txt](https://notes.thecloudspark.com/kcsa/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://notes.thecloudspark.com/kcsa/overview.md).

# Overview

## About KCSA

<div align="center"><figure><img src="https://2019821240-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAffYdhUf4RukFh6IMrh6%2Fuploads%2F3Gc5gOq0Z3okw4fEct2d%2Fkcsa.png?alt=media&amp;token=1f40104f-a807-496d-b956-f674a06746b3" alt="" width="170"><figcaption><p>KCSA Badge<br><em>Reference:</em> <a href="https://www.credly.com/org/the-linux-foundation/badge/kcsa-kubernetes-and-cloud-native-security-associate"><em>https://www.credly.com/org/the-linux-foundation/badge/kcsa-kubernetes-and-cloud-native-security-associate</em></a></p></figcaption></figure></div>

> *The Kubernetes and Cloud Native Security Associate (KCSA) is a pre-professional certification designed for candidates interested in advancing to the professional level through a demonstrated understanding of foundational knowledge and skills of security technologies in the cloud native ecosystem. Reference:* [*CNCF-KCSA*](https://www.cncf.io/training/certification/kcsa/)

## Domains & Competencies

<details>

<summary>Overview of Cloud Native Security 14%</summary>

* The 4Cs of Cloud Native Security
* Cloud Provider and Infrastructure Security
* Controls and Frameworks
* Isolation Techniques
* Artifact Repository and Image Security
* Workload and Application Code Security

</details>

<details>

<summary>Kubernetes Cluster Component Security 22%</summary>

* API Server
* Controller Manager
* Scheduler
* Kubelet
* Container Runtime
* KubeProxy
* Pod
* Etcd
* Container Networking
* Client Security
* Storage

</details>

<details>

<summary>Kubernetes Security Fundamentals 22%</summary>

* Pod Security Standards
* Pod Security Admissions
* Authentication
* Authorization
* Secrets
* Isolation and Segmentation
* Audit Logging
* Network Policy

</details>

<details>

<summary>Kubernetes Threat Model 16%</summary>

* Kubernetes Trust Boundaries and Data Flow
* Persistence
* Denial of Service
* Malicious Code Execution and Compromised Applications in Containers
* Attacker on the Network
* Access to Sensitive Data
* Privilege Escalation

</details>

<details>

<summary>Platform Security 16%</summary>

* Supply Chain Security
* Image Repository
* Observability
* Service Mesh
* PKI
* Connectivity
* Admission Control

</details>

<details>

<summary>Compliance and Security Frameworks 10%</summary>

* Compliance Frameworks
* Threat Modelling Frameworks
* Supply Chain Compliance
* Automation and Tooling

</details>

{% hint style="info" %}
To learn more about KCSA, visit: <https://training.linuxfoundation.org/certification/kubernetes-and-cloud-native-security-associate-kcsa/>
{% endhint %}
