⭐ Trusted by 700+ Buyers  ·  4.7★ Star Seller on Etsy  ·  $9.99/exam  ·  Grab it now →
Home › CNCF › CKA study guide

CNCF Certified Kubernetes Administrator (CKA) Practice Test & Study Guide

Everything you need to plan your CKA prep: the exam format, what each domain covers, a week-by-week study plan, original practice questions, and what thousands of study-group comments reveal about where candidates slip up.

Last updated · By the NotJustExam team

About the CNCF Certified Kubernetes Administrator (CKA) exam

The Certified Kubernetes Administrator (CKA) is a hands-on certification created by the Cloud Native Computing Foundation (CNCF) together with the Linux Foundation. Unlike most IT certifications, the CKA is not a multiple-choice test: candidates work directly in a live terminal against real Kubernetes clusters, completing tasks such as building nodes, configuring RBAC, and diagnosing broken workloads under time pressure. Passing it is widely treated as proof that you can actually operate a cluster, not just describe one.

The exam targets Kubernetes administrators, site reliability engineers, and platform/DevOps engineers who are responsible for installing, configuring, and troubleshooting Kubernetes clusters in production. It assumes comfort with the Linux command line, YAML, and core container concepts, and it does not hold your hand with a GUI — every task is done through kubectl and related CLI tools against the official Kubernetes documentation, which you are allowed to reference during the exam.

CKA matters because it is the most recognized vendor-neutral Kubernetes credential in the industry. Cloud providers, consultancies, and enterprises running their own clusters use it as a baseline signal that a candidate can be trusted with cluster administration duties from day one, and it is frequently listed as a preferred or required qualification in platform engineering job postings.

CNCF CKA (Certified Kubernetes Administrator) exam format at a glance

AttributeDetail (as of 2026, verify on the official page)
Exam codeCKA
FormatPerformance-based; hands-on tasks completed in a live command-line environment against real Kubernetes clusters
Duration2 hours
Passing score66%
CostApproximately 445 USD, which includes one free retake
Kubernetes versionAligned to the current Kubernetes minor version (the exam environment updates 4-8 weeks after each Kubernetes release; v1.35 at time of writing)
DeliveryOnline, remotely proctored, from any location with a supported browser and webcam
Reference materialCandidates may keep the official Kubernetes documentation open in a browser tab during the exam
Validity2 years, renewable by retaking and passing the exam

CNCF CKA (Certified Kubernetes Administrator) domains & what they cover

The CKA curriculum is organized into five domains. The weightings below reflect the published Linux Foundation curriculum; confirm current figures on the official page.

  • Troubleshooting (about 30%) — The largest domain by far: diagnosing broken clusters, nodes, and workloads, reading logs and events, and tracing failures across services and networking. Most of the exam's time pressure comes from this domain.
  • Cluster Architecture, Installation & Configuration (about 25%) — Building and maintaining clusters with kubeadm, managing RBAC, configuring a highly-available control plane, and using Helm/Kustomize and extension interfaces like CNI, CSI, and CRI.
  • Services & Networking (about 20%) — Pod-to-pod connectivity, Network Policies, service types (ClusterIP, NodePort, LoadBalancer), Ingress and the Gateway API, and CoreDNS.
  • Workloads & Scheduling (about 15%) — Deployments, rollouts and rollbacks, ConfigMaps and Secrets, autoscaling, self-healing primitives, and Pod scheduling controls like node affinity and admission.
  • Storage (about 10%) — Storage classes, dynamic volume provisioning, volume types/access modes/reclaim policies, and managing persistent volumes and claims.

How hard is CNCF CKA (Certified Kubernetes Administrator)?

CKA has a reputation as one of the tougher IT certifications precisely because it is performance-based: there is no guessing between four options, and partial credit depends on actually completing the task correctly in a live cluster. Candidates who have only read about Kubernetes, without regularly operating a cluster hands-on, tend to struggle badly on speed and command-line fluency, even if they understand the concepts.

The most common failure mode is running out of time rather than lacking knowledge. Troubleshooting tasks in particular can eat minutes if you are not fast with kubectl, grep, and YAML editing, and a stumble early in the exam can cascade into rushed answers later. Candidates also underestimate how much the exam rewards knowing shortcuts (imperative kubectl commands, aliases, and documentation search skills) over memorized theory.

For someone already administering Kubernetes clusters day to day, a realistic prep window is four to six weeks of focused practice. Candidates newer to Kubernetes, even with solid Linux and container fundamentals, should plan for eight to twelve weeks, most of it spent doing timed hands-on labs rather than reading.

How to prepare for CNCF CKA (Certified Kubernetes Administrator): a study plan

Because the exam is 100% hands-on, your preparation has to be hands-on too — reading alone will not build the speed you need.

  1. Weeks 1–2: Build a working cluster and tour the domains. Set up a local multi-node cluster (kubeadm, kind, or a managed sandbox) and walk through each of the five domains once, running every command yourself rather than just reading about it.
  2. Weeks 3–4: Drill imperative kubectl commands. Practice creating, editing, and troubleshooting resources without YAML templates in front of you. Speed with kubectl run, expose, edit, and explain is what separates comfortable finishes from rushed ones.
  3. Weeks 5–6: Focus on troubleshooting and cluster architecture. These two domains carry over half the exam weight. Practice deliberately breaking things — a bad kubelet config, a misconfigured Service, a stuck Pod — and fixing them under a timer.
  4. Final week: Full timed mock exams. Simulate the real exam length and environment, practice navigating the allowed Kubernetes documentation quickly, and review any task you could not finish inside its fair time share.

Treat practice questions and labs as a way to expose gaps in your muscle memory, not as a score to chase. The goal is to reach a point where the CLI feels like an extension of your thinking rather than something you have to look up.

CNCF CKA (Certified Kubernetes Administrator) FAQ

How much does the CKA exam cost?

The exam is approximately 445 USD as of 2026 and includes one free retake if you do not pass on the first attempt. Pricing and included benefits can change, so confirm the current rate on the official Linux Foundation training page before buying.

Is CKA multiple choice or hands-on?

It is entirely hands-on. You are given a set of tasks to complete on live Kubernetes clusters from a command-line terminal, and your score is based on whether the cluster ends up in the correct state — there are no multiple-choice questions.

How long is the certification valid?

Two years from the date you pass (certifications earned before April 2024 carry a longer legacy validity period). You renew by retaking and passing the exam again before it expires.

Are there prerequisites for CKA?

There are no mandatory prerequisites, so anyone can register. In practice, comfort with the Linux command line and basic container concepts is expected, since the exam gives you no on-ramp once the clock starts.

Can I use documentation during the exam?

Yes. Candidates may keep a browser tab open to the official Kubernetes documentation and a small set of other approved sites during the exam, which rewards being fast at searching docs over memorizing every flag.

Is CKA worth it for a DevOps or platform engineering career?

Generally yes. It is the most widely recognized vendor-neutral Kubernetes credential, it directly validates skills used on the job, and it is commonly listed as a preferred qualification for platform engineering, SRE, and DevOps roles that involve running Kubernetes clusters.

Free CKA practice questions

5 original questions written for NotJustExam from the public CKA exam objectives and independently answer-checked. Try answering before you open the explanation.

Question 1

A Pod's application logs show it is healthy, but a Service meant to route traffic to it never returns a response. Running 'kubectl get endpoints web-svc' shows zero endpoints, and the Service's selector is app: web. What is the most likely cause?

  1. The Pod's labels do not match the Service's selector
  2. The Service's ClusterIP address has expired and needs to be reissued
  3. kube-proxy is not installed on the node running the Pod
  4. The Pod is running with hostNetwork enabled
Show answer & explanation

Answer: A. A Service with zero endpoints almost always means its spec.selector does not match any Pod's labels, since the endpoints controller only adds Pods whose labels satisfy the selector. ClusterIPs do not expire, which makes B a plausible-sounding but incorrect distractor; missing kube-proxy would break routing to existing endpoints rather than produce zero endpoints in the first place.

Source: official documentation

Question 2

You must let a ServiceAccount named ci-deployer create and update Deployments only inside the ci namespace, with no access outside it. Which RBAC setup achieves this?

  1. A ClusterRole granting Deployments permissions, bound cluster-wide with a ClusterRoleBinding
  2. A Role scoped to the ci namespace granting Deployments permissions, bound with a RoleBinding in that namespace
  3. A Role granting Deployments permissions, bound with a ClusterRoleBinding
  4. A ClusterRoleBinding restricted to the ci namespace, referencing a ClusterRole with Deployments permissions
Show answer & explanation

Answer: B. A namespaced Role paired with a RoleBinding in that same namespace grants exactly the scoped access required. Option A grants cluster-wide access, which violates the requirement; option C is invalid because a Role cannot be referenced by a ClusterRoleBinding; option D is impossible because ClusterRoleBindings always apply cluster-wide and cannot be restricted to a single namespace.

Source: official documentation

Question 3

In namespace shop, you apply a NetworkPolicy selecting Pods labeled app: checkout with a single ingress rule allowing traffic from Pods labeled role: frontend. The policy defines no egress rules and no Egress entry in policyTypes. What is the effect on egress traffic leaving the checkout Pods?

  1. All egress traffic from the checkout Pods is denied
  2. Egress is allowed only to Pods labeled role: frontend
  3. Egress is blocked to the internet but allowed within the cluster
  4. All egress traffic from the checkout Pods remains allowed
Show answer & explanation

Answer: D. NetworkPolicy restrictions only apply to the traffic directions listed in policyTypes; since this policy's policyTypes effectively covers only Ingress, egress traffic is left completely unrestricted by it. The common misconception, reflected in option A, is that attaching any NetworkPolicy to a Pod default-denies every direction, but an unspecified direction is simply not touched by that policy.

Source: official documentation

Question 4

A Pod was scheduled using a requiredDuringSchedulingIgnoredDuringExecution node affinity rule requiring the label disktype: ssd. After the Pod is running, an administrator removes the disktype: ssd label from that node. What happens to the already-running Pod?

  1. The scheduler immediately evicts the Pod and reschedules it onto a node with the label
  2. The kubelet restarts the Pod's containers in place to re-evaluate affinity
  3. The Pod continues running on the node, unaffected by the label change
  4. The node is automatically cordoned and drained of all workloads
Show answer & explanation

Answer: C. "IgnoredDuringExecution" means the affinity rule is checked only at scheduling time; once the Pod is bound and running, later changes to the node's labels have no effect on it. Option A describes behavior that would only apply to a RequiredDuringSchedulingRequiredDuringExecution-style rule, which is not how node affinity currently behaves, making it a tempting but incorrect answer.

Source: official documentation

Question 5

A PersistentVolumeClaim requesting 5Gi, ReadWriteOnce, storageClassName fast-ssd stays in Pending status. Describing it reports no matching volume was found. What is the most likely cause?

  1. No PersistentVolume or dynamic provisioner exists that satisfies the requested size, access mode, and storage class
  2. The namespace is missing a ResourceQuota object
  3. The Pod that will consume the PVC has not been created yet
  4. The PVC was created before its consuming Pod, which Kubernetes does not support
Show answer & explanation

Answer: A. A PVC remains Pending until a suitable PersistentVolume already exists or a StorageClass with a working dynamic provisioner can create one that matches the requested capacity, access mode, and class. Creating a PVC before any Pod references it is completely normal and supported, which is why C and D are incorrect despite sounding like reasonable-order-of-operations explanations.

Source: official documentation

What 303 study-group comments reveal about CKA

We summarised the public study-group discussion behind every question in our CKA bank and compared it with an independent AI review. Where they disagree, a posted answer key alone is not enough to trust — which is why every question in the full bank shows the community vote, a discussion summary and a reasoned explanation side by side.

23practice questions reviewed
303study-group comments summarised from Q2 2021 – Q1 2025
0%of questions where the answer commonly posted online is disputed
0%of single-answer questions where the community vote is split

The CKA traps that come up most

  • etcd restore touches data dir and manifest, not app configs — Restoring an etcd snapshot means pointing the etcd static pod manifest at the restored data directory; it does not require editing unrelated Deployments, Services, or other manifests.
  • RBAC scope depends on Role vs ClusterRole pairing — A namespaced Role only grants access when bound with a RoleBinding in that namespace; a ClusterRole bound with a ClusterRoleBinding always applies cluster-wide, so mixing the two does not produce namespace-scoped access.
  • NetworkPolicy only restricts directions it explicitly lists — A NetworkPolicy with only an Ingress rule leaves egress traffic unrestricted, and restricting traffic from another namespace normally requires a namespaceSelector alongside any podSelector, not just a bare podSelector.
  • kubectl drain needs explicit DaemonSet handling — kubectl drain refuses to evict DaemonSet-managed pods unless run with --ignore-daemonsets, and it also cordons the node so no new pods are scheduled there until it is uncordoned.
  • nodeSelector requires the label to exist on the node first — A Pod using nodeSelector stays Pending until a node actually carries the matching label; applying the label after Pod creation lets the scheduler place it, but the label step cannot be skipped.

Inside the full CKA practice bank

  • 23 practice questions in an interactive web app, plus a printable PDF
  • The community-voted answer and a summary of the study-group discussion for each question
  • A step-by-step AI explanation of why the right answer is right — and why the others are not
  • One-time $9.99, lifetime access, no subscription

More certification study guides

Independent study material. NotJustExam is not affiliated with, endorsed by, or sponsored by any certification body; all certification names, trademarks and exam codes belong to their owners and are used for descriptive purposes only. The sample questions on this page are original items written for NotJustExam from the publicly available exam objectives. Exam facts change — always confirm details on the official exam page before you register.