• Home
  • Workshops
  • Services
  • Contact
Mont-Cenis-Straße 399, Herne 44627, Germany
+49 (0) 221 9865099 0
hello@devninjas.io

Workshops

  • Docker Fundamentals
  • Kubernetes Introduction
  • CKAD Exam Prep
  • CKA Exam Prep
  • All Workshops

Services

  • Shogun · Platform Consulting
  • Mamori · Managed Retainer
  • Kensho · Platform Audit

Company

  • Contact
  • Sitemap
2026 • Coded with by DevNinjas
  • Imprint
  • Privacy
  • GTC

Preparation for the Kubernetes and Cloud Native Security Associate (KCSA) Exam

In three days, you prepare specifically for the KCSA certification: all six exam domains, from Cloud Native Security fundamentals to cluster hardening and compliance frameworks. You work hands-on with Falco, OPA Gatekeeper, and Trivy in your own cloud environment.

Share via email
  • Workshop levelSome practical experience recommended
  • Satisfied participants2340+
  • Days3
  • LanguageGerman & English
  • Workshop codeDW25

Workshop Details

What makes this workshop stand out

🎯

What you will learn and take away

After three days of KCSA preparation, you know all six exam domains and can apply Kubernetes security concepts in practice. Here is what you take away:

  • Understand cluster hardening: From API server configuration to etcd encryption and Pod Security Standards, you know where attack surfaces are and how to close them
  • Use security tools: Falco for runtime detection, OPA Gatekeeper for policy enforcement, and Trivy for image scanning are no longer just buzzwords
  • Be exam-ready: Domain weightings, question types, and time management for the 60 MC questions in 90 minutes are practiced

All exercises run in our cloud environment. No local setup, no hassle.

Want to continue after KCSA? Our CKS Workshop builds directly on it and is the next step in the Kubernetes security path.

💼

Why the investment pays off

Kubernetes without security competence in your team means open flanks: misconfigurations that only surface during audits, and incidents that take longer than necessary. This KCSA training changes that:

  • Anchor security awareness in your team: Your employees understand the 4Cs of Cloud Native Security and can assess risks in your own infrastructure
  • Make compliance demonstrable: With knowledge of CIS Benchmarks, NIST, and GDPR requirements, your team can prepare audits and document measures
  • Certification as proof of qualification: The CNCF's KCSA certification is a recognized credential for Kubernetes security fundamentals

Small groups of maximum 8 participants so we can address questions from your specific project context.

📋

Prerequisites

Required:

  • Basic Kubernetes knowledge: You know what Pods, Deployments, Services, and Namespaces are
  • Experience working on the Linux command line
  • Basic understanding of networking concepts (TCP/IP, DNS, firewalls)

Not required:

  • Experience with Kubernetes security tools (covered in the workshop)
  • Programming skills
  • CKA or CKAD certification

Our Kubernetes Fundamentals Training provides ideal preparation if you want to refresh your Kubernetes knowledge.

Workshop Agenda

Your Agenda at a Glance

Hands-on and structured. Every participant works in their own cloud environment. The agenda shows you what to expect each day.

Day 1: Understand Cloud Native Security and secure Kubernetes cluster components

5 topics
09:00–10:00💬 Introduction Round

Cloud, Cluster, Container, Code: each layer has its own security requirements, and a weakness in an outer layer cannot be compensated by the inner one. You will learn the shared responsibility model between cloud provider and operator, and analyze which infrastructure security controls (network segmentation, IAM, firewalls) matter in practice. By the end of this block, you can map an existing architecture to the four layers and systematically identify security gaps.

Which base image is secure, and how do you detect known vulnerabilities before a container runs in production? You will scan images with Trivy, evaluate CVE results, and define policies for approved base images. Additionally, you will see how image signing with Cosign secures the supply chain and why a private registry is part of any standard infrastructure.

trivyTrivy
12:00–13:00🥪 Lunch Break

The API Server is the central gateway to your cluster. You will examine its authentication and authorization chains, inspect TLS configurations, and understand why etcd encryption at rest is not optional. You will also see how the Controller Manager and Scheduler are secured and which flags make a real difference in practice.

At the worker node level, the Kubelet configuration determines the security of all running pods. You will check which Kubelet flags prevent anonymous access, how the container runtime (containerd) provides isolation, and what role KubeProxy plays in network security. In practice, you analyze a node configuration and identify hardening measures.

How does traffic flow between Pods, and where do attack surfaces emerge? You will look at the Kubernetes networking model, the role of CNI plugins, and why storage encryption is necessary for persistent data. You will also secure access via kubectl and kubeconfig: separating contexts, managing certificates, and minimizing cluster access.

16:00–16:30💭 Questions & Answers

Day 2: Configure security fundamentals and analyze threat models

5 topics
09:00–10:00💭 Questions & Answers

Kubernetes ships with three Pod Security Standards profiles: Privileged, Baseline, and Restricted. You will configure Pod Security Admissions in the cluster and test how the enforce, audit, and warn modes respond to non-compliant pods. Afterward, you will know which profile fits which workload and how to roll out the standards incrementally.

Who is allowed to do what in the cluster? You will work with the three authentication methods (X.509 certificates, bearer tokens, OIDC) and then build RBAC roles and RoleBindings. Along the way, you will see common misconfigurations: overly broad ClusterRoles, missing namespace separation, and why system:masters is a risk.

12:00–13:00🥪 Lunch Break

Secrets in Kubernetes are only Base64-encoded by default, not encrypted. You will enable encryption at rest with an EncryptionConfiguration, compare alternatives like Sealed Secrets, and learn why namespace-based isolation combined with ResourceQuotas and LimitRanges is the first line of defense. Finally, you set up audit logging to make security-relevant API calls traceable.

Without NetworkPolicies, every pod can communicate with every other pod. You will implement a default-deny strategy and selectively open ingress and egress rules for your workloads. In practice, you write policies for a microservice scenario, test connections with curl and kubectl exec, and verify that only permitted traffic flows.

Where are the trust boundaries in a Kubernetes cluster, and how does an attacker move laterally after initial access? You will analyze real attack scenarios: privilege escalation through overprivileged service accounts, persistence via tampered container images, and lateral movement in the cluster network. Then you map countermeasures (RBAC, network policies, pod security) to each attack vector.

16:00–16:30💭 Questions & Answers

Day 3: Implement platform security, verify compliance and prepare for the exam

5 topics
09:00–10:00💭 Questions & Answers

Falco detects suspicious behavior at runtime by monitoring system calls via eBPF. You will deploy Falco using a Helm chart in your cluster, write custom rules (e.g., detecting shell access in containers), and configure alerts. You will understand the difference between signature-based and behavior-based detection and when each approach applies.

falcoFalco

Admission controllers validate every request to the API server before it is persisted. You will install OPA Gatekeeper, write ConstraintTemplates in Rego, and enforce policies (e.g., no containers running as root, only approved registries). You will also compare this approach with Kyverno, which uses YAML instead of Rego.

opaOPA GatekeeperkyvernoKyverno
12:00–13:00🥪 Lunch Break

Secure software starts before deployment: you trace the path from code through the build system into the cluster and identify attack points in the supply chain. You will learn about SBOM concepts and image signing with Cosign. In parallel, you understand how PKI and TLS/mTLS encrypt communication in the cluster and what role a service mesh plays.

Which compliance requirements apply to Kubernetes clusters, and how do you prove adherence? You will work with the NIST, PCI DSS, and GDPR frameworks and map their requirements to specific Kubernetes configurations. In practice, you run kube-bench against the CIS Kubernetes Benchmarks and learn how STRIDE and OCTAVE support structured threat analysis.

The KCSA exam consists of 60 multiple-choice questions in 90 minutes with a passing score of 75%. You will review the domain weightings, identify your strengths and weaknesses, and work through sample questions from all six domains. Additionally, you will discuss time management strategies and learn how the exam process (online proctoring, PSI Bridge) works.

16:00–16:30💭 Questions & Answers

Our Benefits

All from one hand!

With our high-quality trainings and workshops, you can bring yourself and your team up to date. All this with many benefits that you get from us.

👨‍💻High Practical Content
70% hands-on, 30% theory. You work continuously with real scenarios and take working code home with you. No PowerPoint battles, but directly applicable knowledge for your projects.
☁️Cloud Learning Environment
DevNinjas Dojo: Your own Kubernetes clusters and VMs for each participant in the browser. No installation, works despite VPN/proxy/firewalls. You work with dedicated resources, not in shared environments.
🥷Experienced Trainers
Full-time DevOps engineers and consultants from DevNinjas lead the workshops. Not external trainers, but specialized employees actively working on client projects and sharing real-world experience.
👥Small Groups
Maximum 8 participants per workshop. Everyone gets individual support from the trainer. Your specific questions and use cases get answered, not passed over in anonymous crowds.
🏗️Real-World Scenarios
No toy examples or hello-world demos. You work with production-grade setups: multi-container applications, CI/CD pipelines, monitoring stacks. Directly transferable to your production environments.
🎓Certification
You receive an official certificate of attendance as PDF and a verified LinkedIn badge. Document your professional development for your employer, HR, and recruiters professionally.

Testimonials

How participants experience our trainings

4.9/ 5

1047+ participant reviews · unfiltered

across all DevNinjas trainings

Trainer
5.0
Content
4.8
Hands-on
4.8

DevNinjas overall: over 1,384 participants · 207 companies · 241 workshops

Including BMW, Bundeswehr, Deutsche Bahn and many more.

"My colleagues specifically looked for a sysadmin course for Docker with another provider and had an instructor who only set up an IDE for them and then only worked on a task sheet with development tasks. I had a course with lots of background information, an instructor who had a really extensive knowledge of the whole subject matter beyond the slides, and I feel optimally informed."

Default avatar picture of DevNinjas
Johannes Bernstein
@TRIMET Gelsenkirchen SE

"The CKS extends your Kubernetes knowledge with the security-relevant aspects and is therefore the perfect follow-up to the CKA. For anyone working in the Kubernetes security space, it is definitely worth it. Very strong technical expertise, very friendly, and the content was conveyed interactively and vividly. The learning environment was very well designed."

Default avatar picture of DevNinjas
Fabian Maas
@STACKIT GmbH

"The "Docker & Kubernetes Bundle" training provided me with solid, practical knowledge for everyday work and enabled me to handle Docker and Kubernetes professionally. The excellently structured material offers real added value, even beyond the workshop. The combination of technical depth and interactive delivery by the trainer rounded off the whole experience. An experience that continues to help me even after the training."

Default avatar picture of DevNinjas
Swen Strangfeld
@Bundesdruckerei GmbH

"It was fun and I learned a lot that I can actually apply directly in my company. The trainer's approach was very hands-on, and he repeatedly brought in real-world examples."

Default avatar picture of DevNinjas
Felix R.
@Dirk Rossmann GmbH

"The seminar gave a very good overview of Docker administration, with a look at Kubernetes and how this knowledge simplifies everyday work. Many small, easy-to-follow examples with hands-on exercises and a focus on best practice consolidated what we learned. The instructor had an answer to every question, and for very specific questions he came back with a fitting example. The alternation between introductions and exercises was very well organised."

Default avatar picture of DevNinjas
Sebastian A.
@DMI GmbH & Co. KG

"The workshop was very informative and I could immediately spot the mistakes I had made in past Docker projects. Before, I lacked the theory and the fundamentals, so I had only been acting on best practice. Now I can write stable Dockerfiles and Docker Compose setups and secure them properly. A very good workshop that was also a lot of fun!"

Default avatar picture of DevNinjas
Timon Strangfeld

"From my perspective, the workshop had the right speed and an appropriate level of challenge. The subject matter was explained clearly by the instructor and practically consolidated with well-distributed exercises. Adjusting the workshop focus to the participants wishes was not a problem. Valuable practical experiences were shared, and even more specific questions were gladly answered. The instructor's professional expertise and extensive practical experience on the subject gave this workshop a special quality."

Default avatar picture of DevNinjas
S. Kaiser
@forcont business technology GmbH

"I can recommend the Docker workshop at DevNinjas without reservation! The training was excellently structured: theory and practice complemented each other perfectly. The trainer always answered questions competently and clearly, making even more complex topics easily accessible. I was especially impressed by the professionally designed workshop materials, which are very useful as a reference even after the course. Overall, a thoroughly successful learning experience!"

Default avatar picture of DevNinjas
Lukas Graf
@Bundeswehr

"I really enjoyed the Docker workshop at DevNinjas! The content was well structured and clearly explained, even for beginners like me. The mix of theory and hands-on exercises was especially helpful for trying Docker directly. By the end, I was able to build my own images, configure containers and set up networks. Absolutely recommended for anyone who wants to learn Docker!"

Default avatar picture of DevNinjas
Pascal Schunk
@OEDIV

"In the workshop the most important Docker and Kubernetes topics were put together, prepared and explained superbly. The exercises fit precisely and were very well chosen in terms of difficulty. I am very satisfied with how much I learned in the five days and feel well prepared for upcoming tasks at work. Sure, you can teach yourself a lot on your own with AI tools, but without the workshop I would not have gained this overview or worked through so many exercises independently."

Default avatar picture of DevNinjas
Christine L.

"Nico is a very friendly and technically skilled instructor. He answered all questions well. You quickly notice that he combines academic expertise with many years of professional practice."

Default avatar picture of DevNinjas
Philipp van Wickevoort Crommelin
@parcIT GmbH

"The workshop gave me a very good insight into Kubernetes and made working with containers much clearer. Nico delivered the content in a practical and well-structured way, so I could quickly find my way around. The hands-on exercises in particular helped me apply what I learned directly. For anyone looking for a solid introduction to Kubernetes, this workshop is definitely recommended."

Default avatar picture of DevNinjas
Daniel Hagen
@DKB Service GmbH

"The advanced Kubernetes workshop at DevNinjas really helped me grow professionally. The content was practical and excellently prepared, so even complex topics like RBAC, network policies and Ingress were conveyed in an understandable and directly applicable way. The deep expertise of the trainer was especially impressive and noticeable in every session. I can recommend this workshop to anyone who wants to use Kubernetes in production!"

Default avatar picture of DevNinjas
Marius Büttner
@Siemens AG

"I really enjoyed the Docker & Kubernetes workshop at DevNinjas. Nico explained the complex topics around containers and orchestration in a very understandable and practical way. The mix of theory and hands-on exercises was perfect for being able to apply everything directly. I was able to take a lot away for my everyday work and now feel significantly more confident working with Docker and Kubernetes."

Default avatar picture of DevNinjas
Dominik Kneissl
@Siemens Healthineers

"The Docker workshop at DevNinjas was an all-round success. The content was clearly structured and practically delivered, including meaningful hands-on exercises. I took away a lot and feel significantly more confident working with Docker. Even more complex topics like multi-stage builds and networking were explained in an understandable way. A clear recommendation for anyone who really wants to understand Docker!"

Default avatar picture of DevNinjas
Daniel Müller
@Siemens Healthineers

"The seminar was superbly prepared, the group pleasantly small and the materials first-class. An excellent instructor who knows the subject inside out, takes time for the participants and answers questions in detail. The learning material alternated in a balanced way between theory and hands-on exercises that were timed excellently."

Default avatar picture of DevNinjas
Kevin H.
@Oest Holding GmbH

Continue Learning

Related Workshops for You

Foundation
Introduction to Kubernetes Workshop
Beginner

Introduction to Kubernetes

Learn to use Kubernetes confidently in three days. From Pods and Deployments to Storage and deployment strategies. You work hands-on in your own cloud environment with kubectl, K9s, and Helm.
3 Days€1,665.00
Next Step
Preparation for the Certified Kubernetes Security Specialist (CKS) Exam Workshop
Advanced

Preparation for the Certified Kubernetes Security Specialist (CKS) Exam

In our four-day CKS workshop, you'll gain hands-on expertise in all relevant security measures and best practices to secure your Kubernetes cluster. Fully prepared to pass the CKS exam with confidence.
4 Days€2,220.00
Alternative
Preparation for the Certified Kubernetes Administrator (CKA) Exam Workshop
Intermediate

Preparation for the Certified Kubernetes Administrator (CKA) Exam

4-day intensive CKA exam prep: Build clusters from scratch, fix production-like failures, secure etcd data, and configure RBAC. After this workshop, you'll master all 5 exam domains (Troubleshooting 30%, Cluster Architecture 25%, Networking 20%, Workloads 15%, Storage 10%) and be ready for certification.
4 Days€2,220.00
Vincent Sturm - DevNinjas

Your Contact

Vincent Sturm

Key Account Manager

Looking for the right Kubernetes or DevOps training for your team? Vincent personally advises you on open workshops, certification prep and customized in-house training. He can also connect you with our consulting services. Get in touch with him directly.

vincent@devninjas.io
+49 221 9865099-4
WhatsApp Chat

Frequently asked questions

No, the KCSA has no formal prerequisites. Unlike the CKS, which requires a valid CKA, you can take the KCSA exam directly. Basic Kubernetes knowledge (Pods, Deployments, Services) is recommended though, so you understand the security concepts in context. Our Kubernetes Fundamentals Training provides ideal preparation if you need the basics.

The KCSA is the entry-level security certification in the CNCF program (associate level, no prerequisites). 60 multiple-choice questions in 90 minutes, 75% to pass. That sounds manageable, and with targeted preparation, it is.

The challenge lies in the breadth: six domains spanning from Cloud Native Security to cluster components and compliance frameworks. Many candidates underestimate how much content sits in the edge areas (threat modeling, supply chain security). In our workshop, we cover all domains systematically so no gaps remain.

KCSA and CKS are both Kubernetes security certifications from the CNCF, but with different focus and format:

KCSA is an associate-level exam with 60 multiple-choice questions in 90 minutes. It tests understanding of security concepts: threat models, compliance frameworks, tools, and best practices.

CKS is a specialist-level exam with performance-based tasks in a real Kubernetes environment. It requires a valid CKA and deep practical experience.

KCSA is ideal as an entry into the security path. Those who want to go deeper can continue with our CKS Workshop.

Yes, three days are realistic for KCSA preparation. The exam tests knowledge of security concepts, not deep practical skills like the CKS. We cover all six domains and work through sample questions in exam format.

Reality check: After three days, you know the entire curriculum and understand how the exam works. For optimal preparation, we recommend reviewing the topics independently in the weeks after the workshop and completing mock exams. The workshop gives you the structure and understanding; independent follow-up solidifies the knowledge.

Around 40% of the workshop time is hands-on practice. The KCSA may be multiple-choice, but anyone who has written Network Policies or configured Falco rules themselves understands the concepts far better than from reading alone. Each participant works in their own cloud environment (no shared lab, no local installation). Live training with an instructor, not pre-recorded videos.

You work hands-on with the most important open-source tools from the CNCF ecosystem:

  • Trivy: Vulnerability scanning for container images and configurations
  • Falco: Runtime security with eBPF-based system call monitoring
  • OPA Gatekeeper: Policy enforcement via admission controllers and Rego
  • kube-bench: Compliance checks against the CIS Kubernetes Benchmarks

Additionally, we cover Kyverno (YAML-based alternative to OPA), Cosign (image signing), and Kubescape (security posture management). All tools are open source with no license costs.

For getting started with security: yes. The KCSA has no admission requirements and gives you the overview of cloud native security before you move on to the hands-on CKS. For administration, the CKA is the better starting point, for development the CKAD.

The complete security path: KCSA, then CKA, then CKS. Holding all five CNCF Kubernetes certifications (KCNA, KCSA, CKA, CKAD, CKS) simultaneously earns you the Kubestronaut title.

Our trainings usually take place from 9:00 to 16:00, both on-site and for public remote trainings.

For corporate trainings, other time models are flexible and can be worked out together.

Our trainings can be held in German or English. Each public date in the date list is labelled with its language. English delivery is additionally available on request at any time, for example as a corporate training.

Yes, upon completion you will receive an official certificate of attendance from DevNinjas as PDF. This confirms your successful participation and the topics covered. The certificate is perfect for conversations with your employer and your personnel file.

Additionally, you will receive a verified digital badge that you can directly embed in your LinkedIn profile (section "Licenses & Certifications"). The badge follows the Open Badges 2.0 standard and is verifiable via QR code at any time. This way you showcase your qualification and position yourself with recruiters.

Workshop Dates

Workshop dates

Choose a suitable date and book directly online. All dates are guaranteed to run.

Guaranteed to runOnly 1 spot left!

10. – 12. August 2026

09:00 - 16:00 (CET/CEST, German time)

Online🇩🇪German

1.665,00 €

per person · plus 19% VAT

Book date
Guaranteed to run

10. – 12. August 2026

09:00 - 16:00 (CET/CEST, German time)

Online🇬🇧English

1.665,00 €

per person · plus 19% VAT

Book date
Guaranteed to runFew spots left

24. – 26. August 2026

09:00 - 16:00 (CET/CEST, German time)

Online🇩🇪German

1.665,00 €

per person · plus 19% VAT

Book date
Guaranteed to run

07. – 09. September 2026

09:00 - 16:00 (CET/CEST, German time)

Online🇩🇪German

1.665,00 €

per person · plus 19% VAT

Book date

Your booking benefits

  • Guaranteed to run

    Every training date takes place: no cancellation due to low participant numbers.

  • Invoice after the workshop

    No prepayment: pay conveniently by invoice afterwards.

  • 3=2

    3-for-2 promotion*

    Register three participants, pay for two: the third seat is free.

  • Price per participant

    Transparent fixed price per participant, plus VAT.

  • No hidden costs

    Cloud lab (DevNinjas Dojo) and all training materials are included in the price.

  • Certificate & Open Badge

    Certificate of attendance plus a digital Open Badge for your LinkedIn profile included.

* Cannot be combined with other discounts.

Tailor a workshop for your team?

Custom content, flexible dates, from 1 participant.

Request