Certified Kubernetes Administrator Free Sample Questions

20 free sample questions199 in the full practice test

Try simulator

CKA Sample Questions

  1. Question 1

    You are hardening a high-availability cluster whose control plane nodes run stacked etcd. After inspecting the static pod manifests in /etc/kubernetes/manifests/, you notice the etcd pod definition is missing a critical parameter for secure communication between members. Which of the following parameters, when correctly configured, ensures that etcd members properly authenticate each other?

    Answer and explanation

    Correct answer: C

    --peer-client-cert-auth=true makes an etcd member check that every incoming peer request (port 2380) presents a valid client certificate signed by the peer CA (--peer-trusted-ca-file). The flag defaults to false, and the etcd docs recommend enabling it to block unauthenticated, forged peers. kubeadm sets it to true in the etcd static Pod, together with --peer-cert-file and --peer-key-file. --listen-client-urls and --advertise-client-urls concern client traffic on port 2379, and --initial-cluster-state (new or existing) only matters when a member bootstraps.

  2. Question 2

    A developer reports that their pod in the dev-ns namespace cannot resolve the service name db-service.prod-ns.svc.cluster.local, despite the service existing and being accessible from pods within the prod-ns namespace. You suspect a NetworkPolicy is interfering. Which of the following NetworkPolicy manifests is the most likely cause of this specific DNS resolution failure?

    Answer and explanation

    Correct answer: C

    When a NetworkPolicy selects Pods for egress, as a default deny-all egress policy in dev-ns does, those Pods may open only the connections that some egress rule allows. The docs caution that 'a default deny-all egress policy also blocks DNS traffic'. Queries from dev-ns Pods to the cluster DNS Service (CoreDNS in kube-system, UDP/TCP port 53) are therefore dropped, and even the FQDN db-service.prod-ns.svc.cluster.local cannot be resolved. The fix is an egress rule that allows port 53 to the CoreDNS Pods, for example namespaceSelector kubernetes.io/metadata.name: kube-system plus podSelector k8s-app: kube-dns. The other policies do not touch the lookup: ingress rules in prod-ns or on dev-ns Pods do not filter the outgoing DNS query, and an egress policy in prod-ns only affects Pods in prod-ns.

  3. Question 3

    You are performing a cluster upgrade from v1.32.5 to v1.33.1 using kubeadm. After successfully upgrading the first control plane node with kubeadm upgrade apply v1.33.1, you proceed to upgrade the worker nodes. The worker's apt source already points to the pkgs.k8s.io v1.33 repository (package index updated), and the Kubernetes packages are not on hold. What is the correct sequence of commands to safely upgrade a worker node named worker-01?

    Answer and explanation

    Correct answer: C

    Worker nodes are upgraded one at a time after the control plane. Drain the node (from a machine with an admin kubeconfig) and upgrade the kubeadm package. Then run kubeadm upgrade node; on a worker it fetches the kubeadm ClusterConfiguration and upgrades the node's kubelet configuration. Upgrade the kubelet and kubectl packages, restart the kubelet and uncordon the node. pkgs.k8s.io package versions look like 1.33.1-1.1, and the docs pin them as '1.33.x-*'. The v1.35 'Upgrading Linux nodes' page drains after kubeadm upgrade node and runs systemctl daemon-reload before restarting the kubelet; draining first is equally safe. The other sequences are wrong. Skipping the drain disrupts running workloads. Upgrading only the kubelet skips kubeadm upgrade node, so the node's kubelet configuration is not upgraded. kubeadm upgrade node runs on the node being upgraded; it cannot target a worker from a control plane node.

  4. Question 4

    A pod is in a CrashLoopBackOff state. Running kubectl logs --previous shows that the application terminated due to a failure to connect to a database. You need to gain interactive access to the pod's environment to test network connectivity using tools like ping and wget, but these tools are not included in the original container image. What is the most effective kubectl command to debug this issue?

    Answer and explanation

    Correct answer: C

    kubectl debug is built for this. kubectl exec needs a running container that already contains the tools, and here the container keeps crashing and lacks them. kubectl attach only connects to the existing process's streams, and port-forward tunnels traffic from your workstation. kubectl debug -it --image=busybox:1.28 --share-processes --copy-to=debug-pod creates a copy of the Pod named debug-pod with an extra busybox container (which provides ping, wget, nc and nslookup) and attaches to it. All containers in the copy share its network namespace, so you can test connectivity to the database from the application's network environment, and --share-processes lets you see the application's processes. The copy is a new Pod with its own IP and, unless you add --keep-labels, without the original labels. To debug inside the original Pod instead, add an ephemeral container with kubectl debug -it --image=busybox:1.28 --target= . Delete debug-pod when you are finished.

  5. Question 5

    You need to create a Kubernetes secret named db-credentials in the backend namespace to store a database username and password. The username is admin and the password is S3cur3P@ssw0rd!. Which imperative command correctly creates this secret directly from the command line, without first writing the credentials to a file?

    Answer and explanation

    Correct answer: A

    kubectl create secret generic with one --from-literal=key=value per key is the documented way to create a Secret from raw data. The password is wrapped in single quotes so that the shell does not interpret special characters such as ! or $. The second command stores the wrong password value (the echoed text password: S3cur3P@ssw0rd! plus a newline), kubectl create secret has no --username/--password flags and needs a subcommand such as generic, and --from-env-file needs a credentials file written beforehand. Values passed on the command line can end up in your shell history, so clear or avoid the history entry when handling real credentials.

  6. Question 6

    Multiple answers

    An administrator needs to deploy a monitoring agent as a DaemonSet to all nodes in the cluster, but the control plane nodes must be excluded. The control plane nodes are labeled node-role.kubernetes.io/control-plane and tainted with node-role.kubernetes.io/control-plane:NoSchedule. Which TWO of the following statements about excluding the control plane nodes are correct? (Select TWO)

    Answer and explanation

    Correct answers: B, E

    The DaemonSet controller adds only a fixed set of tolerations to its Pods: node.kubernetes.io/not-ready and node.kubernetes.io/unreachable (NoExecute), and disk-pressure, memory-pressure, pid-pressure, unschedulable and, for hostNetwork Pods, network-unavailable (NoSchedule). The control-plane taint is not among them, so the existing node-role.kubernetes.io/control-plane:NoSchedule taint already keeps DaemonSet Pods off the control plane nodes; the documentation's example adds an explicit control-plane toleration only to make a DaemonSet run there. To make the exclusion explicit (for example, in case a broad toleration is added later), add required node affinity with key: node-role.kubernetes.io/control-plane and operator: DoesNotExist; the DaemonSet controller creates Pods only on nodes that match the Pod template's node affinity. Adding the toleration would do the opposite, DaemonSets have no replicas field, and taints are not ignored for DaemonSet Pods, so no anti-affinity rule against kube-apiserver Pods is needed.

  7. Question 7

    You are auditing RBAC permissions and need to quickly verify if a specific service account, app-reader in the staging namespace, has permission to get pods in the production namespace. Which command provides a clear 'yes' or 'no' answer to this question?

    Answer and explanation

    Correct answer: B

    The kubectl auth can-i subcommand is specifically designed for this purpose. It allows you to impersonate a user, group, or service account (using the --as flag) and check if they have permission to perform a specific action on a resource. It returns a simple 'yes' or 'no', making it the most direct and efficient way to answer the question.

  8. Question 8

    A new cluster administrator is trying to understand the flow of traffic for a service exposed via NodePort. They observe that a request sent to node-ip:node-port on any node in the cluster correctly routes to a pod, even if that pod is not running on the node that received the request.

    Which component is responsible for this routing behavior across the cluster?

    graph TD Client -->|"Request to Node2_IP:NodePort"| Rules2 subgraph Node2 Rules2["Service forwarding rules on Node2"] end subgraph Node1 TargetPod[Target Pod] end Rules2 -->|"DNAT to the Pod IP, delivered over the Pod network"| TargetPod
    Answer and explanation

    Correct answer: C

    kube-proxy runs on every node and watches Services and EndpointSlices. For a NodePort Service it programs packet-forwarding rules on every node, so every node accepts traffic on the node port. On Linux these are iptables rules by default, or nftables; IPVS mode is deprecated in v1.35. The kernel then DNATs the packet to one of the ready backend Pod IPs, which may be on another node, and the Pod network set up by the CNI plugin delivers it there. kube-proxy does not relay the packets itself. CoreDNS only resolves names. The CNI plugin provides Pod-to-Pod connectivity but not the Service-to-Pod mapping. An Ingress controller handles HTTP routing for Ingress resources, not NodePort traffic.

  9. Question 9

    A critical application is experiencing performance degradation. You suspect a 'noisy neighbor' pod is consuming excessive CPU resources on a worker node. Which kubectl command would you use to identify the pods consuming the most CPU on all nodes in the cluster?

    Answer and explanation

    Correct answer: C

    The kubectl top pods command displays CPU and memory usage for pods. The -A flag (or --all-namespaces) ensures you see pods from all namespaces, and --sort-by=cpu orders the output to show the highest CPU consumers first, making it easy to identify the culprit. This command requires the Metrics Server to be installed in the cluster.

  10. Question 10

    True or False: When using kubeadm with the default kubelet configuration, swap should be disabled on all nodes (both control plane and worker) before running kubeadm init or kubeadm join.

    Answer and explanation

    Correct answer: A

    True. The v1.35 install guide says that 'the default behavior of a kubelet is to fail to start if swap memory is detected on a node', so swap must be either disabled or explicitly tolerated. With the default configuration (failSwapOn: true), disable it on every node with sudo swapoff -a. Then remove the swap entries from /etc/fstab (or disable the systemd swap units) so it stays off after a reboot. Tolerating swap is an explicit opt-in: set failSwapOn: false and, if workloads should use swap, a swapBehavior other than the default NoSwap (swap support is GA since v1.34). kubeadm's own preflight check only warns about swap; it is the kubelet that refuses to start.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 199 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon