KCSA — Kubernetes Security Associate
This Is What the KCSA Exam Looks Like
In one line
KCSA is a multiple-choice exam, and you must score 75% or more within 90 minutes to pass.
Why read this first
The most common failure in certification study is not from not knowing the content but from going in without knowing the shape of the exam. If you do not know what the passing score is, how tight the time is, or which domains have the most questions, you cannot set your preparation priorities.
Official specification
| Item | Value |
|---|---|
| Format | Multiple choice |
| Time limit | 90 minutes |
| Passing score | 75% |
| Number of questions | 60 questions |
| Exam fee | $250 (includes one retake) |
| Validity | 2 years |
These values are taken from the candidate documentation at docs.linuxfoundation.org. The certification
introduction page does not list the passing score or the number of questions, so if you prepare by looking only at that page,
you will walk into the exam room without knowing the passing score.
Domain weighting
| Domain | Weight | Questions in this practice exam |
|---|---|---|
| Overview of Cloud Native Security | 14% | 8 questions |
| Kubernetes Cluster Component Security | 22% | 13 questions |
| Kubernetes Security Fundamentals | 22% | 13 questions |
| Kubernetes Threat Model | 16% | 10 questions |
| Platform Security | 16% | 10 questions |
| Compliance and Security Frameworks | 10% | 6 questions |
More questions come from the domains with larger weights. Use these proportions as the basis when allocating your study time. This practice exam also distributes its questions in the same proportions.
Where answers diverge
When you grade a practice exam, the questions you get wrong cluster in one pattern. You get them wrong not because you do not know the content but because you miss which of two similar concepts is being asked about. When you read a question and one of the pairs below comes to mind, separate them first using the criterion in the third column.
| This | That | What separates them |
|---|---|---|
| PodSecurity admission | SecurityContext | If it is enforced with a namespace label, it is admission |
| Role | ClusterRole | If it crosses namespaces or handles nodes and PVs, it is a ClusterRole |
| NetworkPolicy ingress | egress | If the problem is about blocking what goes out, it is egress |
| Authentication | Authorization | Who you are vs what you can do |
| Signature verification | Vulnerability scan | Proving provenance is signing, and looking at contents is scanning |
| Cluster in 4C | Container | If it is about kubelet or API server settings, it is the Cluster layer |
This does not mean you should memorize the table. If you mark which pair each question you got wrong fell under, the place you need to study again becomes much narrower than a domain name.
What you may consult while answering
In a multiple-choice exam, you cannot look at any material. Documentation, searching, and notes are all disallowed. This is the biggest difference from a hands-on exam.
What you actually experience at the exam
Many people know all the content yet panic over the procedure and lose time.
The exam is taken with online proctoring on PSI's Bridge platform. The proctor's video verification procedure takes up to 30 minutes, and during this time the questions do not open and the time limit does not start. Even so, you should clear your schedule for the 30-minute check-in plus the exam time.
There are four things checked at check-in. Agreeing to the non-disclosure agreement, a government-issued ID that exactly matches the name you registered with, showing the room by panning your webcam, and closing unapproved software. Because of that last item, turning off background programs such as Slack or cloud sync in advance saves time.
There are a few conditions that are easy to trip over when taking the exam in Korea. The ID must be signed, so a passport is the safest. Only one monitor can be used, and a dual monitor is not supported. There must be nothing on the desk or under it, taking notes on paper is prohibited, and reading the questions aloud is not allowed either. On a company network or VPN, AWS S3 access may be blocked and you can get caught in the pre-check.
You can change your reservation only up to 24 hours before the start. And if you book and do not show up, you not only lose the exam fee but also lose your retake eligibility. Results come by email within 24 hours after the exam ends.
The exam fee includes one retake, and you must complete both the exam and the retake within 12 months of the initial purchase date. There is no official waiting period, so you can take it again right after receiving the result. Rather than putting it off because you are not perfectly prepared, it is often better to take it once and see which domain is weak.
The certification is valid for 2 years. Overlapping with this is the CARE program introduced in 2026. If you pass CKA or CKAD, KCNA is automatically renewed, and if you pass CKS, KCSA and CKA are automatically renewed. But you must earn the lower certifications first for this chain to work. If you earn CKA first and KCNA later, KCNA is not renewed by that CKA. If you aim for Golden Kubestronaut, this order decides your renewal burden for the next several years.
How to use this practice exam
The time limit is set the same as the real exam. The remaining time is shown at the top of the screen, and when time is up it is submitted automatically and unanswered questions are treated as wrong. This is because the real exam also grades only what you have answered at that point.
It matters to sit and do it through in one go. If you look things up partway, the score goes up, but that score does not predict the real exam. What you are checking is not whether you know it but whether you clear the passing score within the time limit.
After reading the explanation for a question you got wrong, study again the domain that question belongs to.