
Certified Kubernetes Administrator (CKA)
The Certified Kubernetes Administrator (CKA) certification validates your ability to install, configure, and manage production-grade Kubernetes clusters. It is designed for Kubernetes administrators, cloud administrators, and IT professionals who manage Kubernetes instances. Earning the CKA proves you have the hands-on, command-line skills to operate Kubernetes in real-world environments, making you a recognized expert in the cloud-native ecosystem.
653 practice questions · Updated 2026-07-30
5Domains
27Objectives
209Concepts
653Questions
CKA Curriculum
Every domain, objective, and concept the CKA exam measures.
- StorageClass definition
- Dynamic volume provisioning
- PVC binding to StorageClass
- Default StorageClass
- StorageClass parameters and provisioners
- Reclaim policies
- Volume expansion
- StorageClass and PVC lifecycle
- Volume Types
- Access Modes
- Reclaim Policies
- PersistentVolume and PersistentVolumeClaim Configuration
- Storage Classes
- Binding and Lifecycle
- Persistent Volumes (PVs)
- Persistent Volume Claims (PVCs)
- PV to PVC Binding
- Access Modes
- Storage Classes
- Dynamic Provisioning
- Static Provisioning
- Reclaim Policies
- PVC Lifecycle
- Pod Volume Mounting
- Volume Modes
- Resizing PVCs
- Cluster health assessment
- Node status diagnosis
- Control plane troubleshooting
- Worker node troubleshooting
- Network troubleshooting
- Storage troubleshooting
- Log and event analysis
- Recovery and remediation
- Identify failing cluster components
- Troubleshoot control plane components
- Troubleshoot worker node components
- Troubleshoot networking components
- Use kubectl and logs for diagnosis
- Restart and recover failed components
- Monitor cluster resource usage
- Monitor application resource usage
- Interpret resource metrics
- Identify resource bottlenecks
- Understanding container output streams
- Viewing container logs
- Following logs in real-time
- Accessing logs from previous container instances
- Selecting containers in multi-container pods
- Managing log output volume
- Redirecting and capturing output streams
- Troubleshooting with output streams
- Service DNS resolution
- Service endpoint connectivity
- Network policy enforcement
- Ingress controller troubleshooting
- kube-proxy and iptables/IPVS
- CNI plugin issues
- Cluster DNS configuration
- Service type and port mapping
- Deployment Basics
- Creating Deployments
- Scaling Deployments
- Rolling Update Strategy
- Performing Rolling Updates
- Rollback Mechanisms
- Checking Rollout Status
- Pausing and Resuming Rollouts
- Create ConfigMaps
- Create Secrets
- Consume ConfigMaps as environment variables
- Consume Secrets as environment variables
- Consume ConfigMaps as volumes
- Consume Secrets as volumes
- Use ConfigMaps for command-line arguments
- Use Secrets for private registry authentication
- Understand ConfigMap and Secret immutability
- HorizontalPodAutoscaler (HPA) basics
- HPA configuration
- HPA metrics types
- HPA behavior and tuning
- HPA status and troubleshooting
- Autoscaling with kubectl
- Deployment primitives
- ReplicaSet mechanics
- Pod lifecycle and restart policies
- Liveness probes
- Readiness probes
- Startup probes
- Rolling updates and rollbacks
- Resource requests and limits
- Pod disruption budgets
- Horizontal pod autoscaling
- Pod Admission Control
- Resource Requests and Limits
- LimitRange
- ResourceQuota
- Node Affinity
- Pod Affinity and Anti-Affinity
- Node Selector
- Taints and Tolerations
- Scheduling with Node Name
- Scheduler Configuration and Priority
- RBAC Overview
- Role and ClusterRole
- RoleBinding and ClusterRoleBinding
- RBAC Permissions and Verbs
- Service Accounts
- RBAC Verification
- Network prerequisites
- Firewall and port requirements
- Container runtime installation
- System package and dependency setup
- Swap and kernel module configuration
- Load balancer preparation
- DNS and certificate prerequisites
- Storage and volume prerequisites
- kubeadm init
- kubeadm join
- kubeadm token management
- kubeadm configuration file
- Control plane components
- kubeadm upgrade
- kubeadm reset
- High availability with kubeadm
- Cluster networking setup
- Troubleshooting kubeadm clusters
- Cluster Upgrade Planning
- Upgrade Control Plane Components
- Upgrade Worker Nodes
- Cluster Backup and Restore
- Cluster Maintenance
- Cluster Scaling
- Cluster Configuration Management
- High-Availability Control Plane Architecture
- etcd Cluster Configuration
- Load Balancing the API Server
- Leader Election for Control Plane Components
- Stacked etcd vs External etcd Topology
- Control Plane Node Provisioning
- Verifying Control Plane Health
- Upgrading a Highly-Available Control Plane
- Helm basics
- Helm chart structure
- Helm install and upgrade
- Helm values and overrides
- Helm rollback and uninstall
- Kustomize basics
- Kustomize overlays and bases
- Kustomize common transformers
- Kustomize patches
- Kustomize build and apply
- CNI (Container Network Interface)
- CSI (Container Storage Interface)
- CRI (Container Runtime Interface)
- Extension Interfaces Overview
- Define Custom Resource Definitions (CRDs)
- Create and manage CRDs
- Understand custom resources and their lifecycle
- Explain the role of operators in Kubernetes
- Install an operator using the Operator Lifecycle Manager (OLM)
- Configure an operator
- Manage operator lifecycle
- Pod Networking Model
- Pod-to-Pod Communication
- Service Abstraction
- Service Types
- DNS for Services and Pods
- Network Policies
- Ingress Controllers and Resources
- CNI Plugins
- NetworkPolicy fundamentals
- Pod and namespace selectors
- Policy types and direction
- Rule fields and semantics
- Default deny policies
- Policy enforcement and interaction
- Testing and troubleshooting
- ClusterIP service
- NodePort service
- LoadBalancer service
- Service types comparison
- Endpoints object
- Service to pod selection
- Service discovery and DNS
- Gateway API fundamentals
- GatewayClass configuration
- Gateway resource configuration
- HTTPRoute configuration
- Traffic routing and matching
- Backend service selection
- Gateway API vs Ingress
- Applying Gateway API resources
- Ingress controllers
- Deploying an Ingress controller
- Ingress resources
- Path-based routing
- Host-based routing
- TLS termination
- Default backend
- Annotations
- Ingress classes
- Troubleshooting Ingress
- CoreDNS role in Kubernetes
- CoreDNS configuration
- CoreDNS deployment
- DNS resolution for Services and Pods
- CoreDNS troubleshooting
- Customizing CoreDNS
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CKA, so none is invented.