CKA · Intermediate
Certified Kubernetes Administrator
Administer Kubernetes clusters, workloads, networking and storage, and diagnose control-plane and application failures.
Your free account includes a full CKA practice exam.
ExamNova practice
Your first session
- Questions
- 60
- Time limit
- 90 min
- Coverage
- 5 domains
Practise, review your answers and see where to focus next.
Is CKA your next step?
Explore the coverage below to see how this certification fits your study goals.
What you’ll study
Your CKA practice covers every domain on the exam.
- Cluster Architecture, Installation and Configuration
- Workloads and Scheduling
- Services and Networking
- Storage
- Troubleshooting
Consult the official guide for the vendor’s current exam outline.
Put it into practice.
Explore hands-on tasks connected to CKA. These are real Labs from the catalogue.
Restore application configuration without leaking credentials
Repair catalog.yaml. Preserve the store/catalog Deployment (apps/v1), two replicas, catalog container, registry.example/catalog:8 image, catalog-runtime account, and matching Deployment/template labels. Supply APP_MODE=production and API_URL=https://orders.store.svc from ConfigMap data, and API_TOKEN=demo-credential-7A from an Opaque Secret. The credential is an inert practice value. Objects and references are namespace-local; keep their namespace explicit. The supplied application first reads each direct environment variable; if absent, it reads the file named by the corresponding APP_MODE_FILE, API_URL_FILE or API_TOKEN_FILE variable. It starts successfully only when all three resulting values match these facts and every required environment, projection and mount dependency is available. Optional missing references can be skipped by Kubernetes but cannot supply an absent required application value. Public inputs must originate in ConfigMaps and private inputs in Secrets, even if a copied literal could technically start the process. Keep the credential and its base64 representation out of ConfigMaps, workload literals and metadata. Resolve inputs through key references/envFrom, mapped ConfigMap/Secret volumes, or a mixture. Explicit env overrides envFrom; later envFrom imports override earlier imports. Secret stringData overrides same-key decoded data. The supported manifest subset is Deployment identity/selectors, env/envFrom, ConfigMap data, Opaque Secret data/stringData, and non-overlapping config/secret mounts with optional items/subPath. Other Pod features and shell expansion are outside the model. Inspect unresolved-reference evidence and repair without Reset.
easy · About 30 min
LabRecover static API-server paths, TLS and persistent audit output
Repair apiserver.yaml for kube-system/kube-apiserver, its kube-apiserver container and image registry.k8s.io/kube-apiserver:v1.35.4. Preserve hostNetwork:true, Always restart, direct kube-apiserver execution, --advertise-address=192.0.2.10 and --secure-port=6443. Keep Node,RBAC authorization. The static manifest cannot depend on API ConfigMaps, Secrets or ServiceAccounts. Observed host inventory: /etc/kubernetes/pki/current has apiserver.crt/key (matching serving-current, cluster-ca issuer, serverAuth, SANs api.example.test and 192.0.2.10, validity 0..100 inclusive), ca.crt (cluster-ca), etcd-ca.crt (etcd-ca), and apiserver-etcd-client.crt/key (matching etcd-client, etcd-ca issuer, clientAuth, validity 0..100). /etc/kubernetes/pki/archive has an otherwise valid matching apiserver.crt/key pair expiring at 20. Independent cold starts occur at 10 and 30. Supply --tls-cert-file, --tls-private-key-file, --client-ca-file, --etcd-cafile, --etcd-certfile and --etcd-keyfile as readable container paths resolving to the correct host files. Required credential and policy mounts must be readOnly:true. Healthy etcd is https://127.0.0.1:2379 in both phases. /etc/kubernetes/audit/policy.yaml contains required metadata-policy. Resolve --audit-policy-file to it, and --audit-log-path to a writable file directly inside /var/log/kubernetes; preserve that host directory for persistence. Use existing File/Directory hostPath mounts, either directories or individual files. Container paths may vary. Compare resolved host paths, pair loadability, client TLS, etcd readiness and audit writability; repair the later cold start without Reset.
hard · About 40 min
Make CKA your next step.
Create your free account. Start practising.
Start Free