KubeRusted
Spinning up your cluster…

CKAD exam prep — Certified Kubernetes Application Developer

Free CKAD (Certified Kubernetes Application Developer) practice: the 5 official domains, exam-style questions, a timed practice exam and more.

Play the CKAD map → · Official CKAD exam page

Application Design and Build (20%)

Container images, the right workload resource, multi-container Pods, volumes

Application Deployment (20%)

Rolling updates, blue/green and canary with primitives, Helm and Kustomize

Application Observability and Maintenance (15%)

API deprecations, probes, CLI monitoring, logs and debugging

Application Environment, Configuration and Security (25%)

CRDs, auth, requests/limits/quotas, ConfigMaps, Secrets, ServiceAccounts, SecurityContexts

Services and Networking (20%)

NetworkPolicies, Services and Ingress rules

Practice questions

Which kubectl command generates a Pod manifest without creating anything?

Answer: kubectl run web --image=nginx --dry-run=client -o yaml. Redirect it to a file (> pod.yaml), edit, then kubectl apply -f.

A Job must run 5 Pods to completion, at most 2 at a time. Which fields?

Answer: completions: 5 and parallelism: 2. backoffLimit controls retries on failure, not the number of completions.

What does a Job’s backoffLimit control?

Answer: How many times failed Pods are retried before the Job is marked failed. activeDeadlineSeconds limits total duration instead.

Which CronJob field stops a new run from starting while the previous one is still running?

Answer: concurrencyPolicy: Forbid. Replace would kill the running Job and start a new one; Allow (default) runs them side by side.

Which restartPolicy values are valid for a Job’s Pod template?

Answer: OnFailure; Never. Jobs need Pods that eventually stop; Always is for long-running workloads.

What is a native sidecar container?

Answer: An init container with restartPolicy: Always that keeps running alongside the app. It starts before the app containers and is stopped after them.

Two containers in a Pod need a shared scratch directory. What do you add?

Answer: An emptyDir volume mounted in both containers. emptyDir is created with the Pod and shared by all its containers.

In a Dockerfile, what is the difference between CMD and ENTRYPOINT?

Answer: ENTRYPOINT sets the executable; CMD supplies default arguments that are easy to override. In Kubernetes, command overrides ENTRYPOINT and args overrides CMD.

In a Pod spec, which field overrides the image’s ENTRYPOINT?

Answer: command. args overrides the image’s CMD.

Which command shows the revision history of Deployment web?

Answer: kubectl rollout history deployment/web. Add --revision=N to see one revision’s Pod template.

How do you pause a rollout to make several changes before resuming?

Answer: kubectl rollout pause deployment/web, then kubectl rollout resume. Changes made while paused roll out together on resume.

Which command restarts all Pods of a Deployment without changing its spec?

Answer: kubectl rollout restart deployment/web. It adds a restartedAt annotation to the Pod template, triggering a rolling update.

With replicas: 4, maxSurge: 1, maxUnavailable: 0, how many Pods can exist at most during a rollout?

Answer: 5. maxSurge allows one Pod above the desired count; none may be unavailable.

How do you implement blue/green with plain Kubernetes objects?

Answer: Run both Deployments and switch the Service selector from version: blue to version: green. Deployment has only RollingUpdate and Recreate strategies.

Which Helm command upgrades release web to a new chart version, installing it if missing?

Answer: helm upgrade --install web <chart>. A common idempotent pattern in pipelines.

Which Helm command rolls release web back to revision 2?

Answer: helm rollback web 2. helm history web lists the revisions.

Which Helm command lists releases in all namespaces?

Answer: helm list -A. -A is short for --all-namespaces.

In a kustomization.yaml, which field changes an image tag without editing the base manifests?

Answer: images. images: [{name: nginx, newTag: 1.27}] rewrites matching image references.

Which probe type checks a gRPC health endpoint natively?

Answer: grpc. Kubernetes supports grpc probes against the gRPC Health Checking Protocol.

A liveness probe fails 3 times in a row with failureThreshold: 3. What happens?

Answer: The kubelet restarts the container. Restart follows the Pod’s restartPolicy.

How do you follow the logs of all Pods labelled app=web?

Answer: kubectl logs -l app=web -f. Add --all-containers or -c to pick containers.

How do you list Pods together with their node and IP?

Answer: kubectl get pods -o wide. -o wide adds node, IP and nominated node columns.

How do you find which API version to use for a resource in your cluster?

Answer: kubectl explain <kind> (or kubectl api-resources). explain shows the KIND and VERSION header for the served version.

Which command opens a shell in container sidecar of Pod web?

Answer: kubectl exec -it web -c sidecar -- sh. -c selects the container; -- separates kubectl flags from the command.

Which command creates a ConfigMap from a file app.properties?

Answer: kubectl create configmap app --from-file=app.properties. The key defaults to the file name.

How do you load every key of ConfigMap app as environment variables?

Answer: envFrom with configMapRef name: app. Keys that are not valid variable names are skipped.

Which command creates a TLS Secret?

Answer: kubectl create secret tls web-tls --cert=tls.crt --key=tls.key. The Secret type is kubernetes.io/tls with keys tls.crt and tls.key.

How do you decode the password key of Secret db?

Answer: kubectl get secret db -o jsonpath='{.data.password}' | base64 -d. describe shows only sizes, not values.

How do you give a Pod a specific ServiceAccount?

Answer: spec.serviceAccountName: <name>. The ServiceAccount must exist in the Pod’s namespace.

Which SecurityContext setting lets a container bind port 80 without running as root?

Answer: capabilities.add: ['NET_BIND_SERVICE']. Ideally drop: ["ALL"] and add back only NET_BIND_SERVICE.

Which Pod-level SecurityContext field sets the group owner of mounted volumes?

Answer: fsGroup. Volumes that support ownership management are chowned to fsGroup.

A container must not be able to write to its own filesystem. Which field?

Answer: readOnlyRootFilesystem: true. Mount an emptyDir where it still needs to write (e.g. /tmp).

What does a LimitRange do in a namespace?

Answer: Sets default requests/limits and min/max per container or Pod. ResourceQuota caps totals; LimitRange shapes individual objects.

Which ResourceQuota field limits the number of Pods in a namespace?

Answer: pods. Object counts like pods, services or count/deployments.apps can be capped.

What is the QoS class of a Pod whose containers all have requests equal to limits for CPU and memory?

Answer: Guaranteed. Burstable has some requests or limits; BestEffort has none.

Which object discovers and uses an Operator’s API, e.g. a Postgres cluster?

Answer: A custom resource of the kind defined by the operator’s CRD. You create the custom resource; the operator reconciles it.

Which command creates a ClusterIP Service named api on port 80 targeting 8080, selecting app=api?

Answer: kubectl create service clusterip api --tcp=80:8080. create service sets the selector app=api from the name; kubectl expose copies an existing workload’s selector.

A NodePort Service has nodePort 31080. How do clients outside the cluster reach it?

Answer: Any node’s IP on port 31080. NodePort opens the same port on every node.

Which command tests a Service from inside the cluster with a throwaway Pod?

Answer: kubectl run tmp --rm -it --image=busybox --restart=Never -- wget -qO- http://api. --rm deletes the Pod when the command exits.

What pathType matches /api, /api/ and /api/v1 but not /apiv2?

Answer: Prefix. Prefix matches by path elements split on /.

Which Ingress field references the Secret used for HTTPS?

Answer: spec.tls[].secretName. The Secret must be of type kubernetes.io/tls in the Ingress’s namespace.

A NetworkPolicy allows ingress to app=db only from app=api. A Pod labelled app=web tries to connect. Result?

Answer: Denied. Once db Pods are selected for ingress, only the listed sources may connect.

Which policyTypes must a policy declare to restrict outgoing traffic?

Answer: Egress. Without Egress in policyTypes, a policy does not restrict outgoing traffic.

How do you allow traffic from all Pods in namespace monitoring to app=web?

Answer: An ingress rule with namespaceSelector matching kubernetes.io/metadata.name: monitoring. Every namespace carries the immutable kubernetes.io/metadata.name label.

What DNS name does a Pod use to reach Service api in its own namespace?

Answer: api. The short name resolves via the Pod’s DNS search domains.

Which command shows the endpoints (Pod IPs) behind Service api?

Answer: kubectl get endpointslices -l kubernetes.io/service-name=api. kubectl describe svc api also lists endpoints.

A report must run every night at 02:00 and exit when done. Which resource fits?

Answer: CronJob. CronJob creates a Job on a schedule ("0 2 * * *"); Jobs run Pods to completion instead of keeping them running.

The app container must not start until a migration script has finished. What do you use?

Answer: An init container that runs the migration. Init containers run to completion, in order, before app containers start. Pods have no ordering across Deployments.

Two containers in one Pod must share files that can be thrown away with the Pod. Which volume?

Answer: emptyDir. emptyDir lives exactly as long as the Pod and is shared by its containers. hostPath ties you to a node; a PVC persists.

With only built-in primitives, how do you send roughly 10% of traffic to a new version?

Answer: Run 1 Pod of the new version and 9 of the old behind one Service selector. Services spread connections across all matching endpoints, so the split follows replica counts. Weighted routing needs Gateway API, a mesh or Argo Rollouts.

Which command installs the chart podinfo/podinfo as release "web" in namespace web, creating the namespace?

Answer: helm install web podinfo/podinfo -n web --create-namespace. `helm install <release> <chart>`; `helm create` scaffolds a new chart, it does not install one.

Deployment "web" must never drop below its desired replica count during an update. Which setting?

Answer: strategy.rollingUpdate.maxUnavailable: 0. maxUnavailable: 0 (with maxSurge ≥ 1) only removes an old Pod once a new one is available. Recreate stops everything first.

An app needs 2 minutes to warm up, and the liveness probe keeps killing it before then. Best fix?

Answer: Add a startupProbe that allows enough time before liveness checks begin. A startupProbe disables liveness and readiness checks until it succeeds, which is exactly for slow starters.

A Pod is Running but receives no traffic from its Service. Which probe is the likely reason?

Answer: A failing readiness probe. Not-ready Pods are removed from the Service endpoints but are not restarted. A failing liveness probe would restart it instead.

`kubectl apply` fails with: no matches for kind "Deployment" in version "extensions/v1beta1". What do you do?

Answer: Change apiVersion to apps/v1 (and add the now-required selector). That API version was removed. The deprecation guide lists replacements; apps/v1 Deployments require spec.selector.

In a namespace with a compute ResourceQuota, a Pod without resources is rejected. Least-effort fix for every future Pod?

Answer: Create a LimitRange that sets default requests and limits. A LimitRange injects defaults at admission time, so Pods without resources pass the quota check.

Expose key DB_PASS of Secret "db" as an environment variable. Which field?

Answer: env[].valueFrom.secretKeyRef with name db and key DB_PASS. secretKeyRef picks a single key. envFrom.secretRef imports every key and has no key field.

A container must run as a non-root user and be unable to gain privileges. Which settings?

Answer: runAsNonRoot: true (with runAsUser set to a non-zero UID); allowPrivilegeEscalation: false. Both are SecurityContext fields. The wrong options all increase privileges.

The Service sends to port 80 but the app listens on 8080. Which Service field must be 8080?

Answer: targetPort. port is the Service’s own port; targetPort is the Pod port it forwards to.

Block all ingress to every Pod in a namespace, then allow only what you need. The first policy is:

Answer: podSelector: {} with policyTypes: [Ingress] and no ingress rules. An empty podSelector selects every Pod; with no rules nothing is allowed. `ingress: [{}]` would allow everything.