Free CNPA (Certified Cloud Native Platform Engineering Associate) practice: the 6 official domains, exam-style questions, a timed practice exam and more.
Play the CNPA map → · Official CNPA exam page
Declarative management, DevOps, environments, platform architecture, goals, CI, CD and GitOps
Traces/metrics/logs/events, secure service communication, policy engines, K8s and CI/CD security
CI pipelines, incident response, CI/CD relationship, GitOps workflows and environments
Reconciliation loop, CRDs as self-service APIs, infrastructure provisioning, operators
Simplified access, API-driven service catalogs, developer portals, AI/ML in automation
Platform efficiency, team productivity, DORA metrics
Answer: An integrated collection of capabilities defined and presented according to the needs of its users. Capabilities are offered consistently, with interfaces and documentation.
Answer: Application and product teams inside the organization. The platform team builds for internal developers as its customers.
Answer: Provisioning databases on demand; Observability for every service; CI/CD pipelines. Capabilities are reusable building blocks app teams consume.
Answer: Start with the smallest set of capabilities that delivers value, then grow it. A wiki page of standards can be a first platform.
Answer: Optional platforms must earn users by being better, which keeps the team user-focused. Mandates hide whether the platform actually helps.
Answer: Providing X-as-a-Service to stream-aligned teams. Enabling teams help others adopt new practices for a while.
Answer: Too much cognitive load and duplicated infrastructure work in app teams. Consistent self-service capabilities reduce both.
Answer: Self-service APIs and products instead of manual request queues. Platform as a product: capabilities are consumed on demand through interfaces, not requested through queues.
Answer: Describing desired state and letting controllers converge actual state to it. The Kubernetes API model.
Answer: Declared state can be versioned, reviewed, reconciled and recreated. Drift is detectable when desired state is declared.
Answer: Consistent, reproducible places (dev, staging, prod) to run and promote applications. Platforms often offer ephemeral preview environments too.
Answer: Automation and shared ownership of delivery. Platforms scale DevOps practices across many teams.
Answer: Merging changes frequently with automated builds and tests. Fast feedback on every change.
Answer: Keeping software always releasable, delivering through automated pipelines. GitOps is one implementation of CD.
Answer: Delivering apps and platform config from versioned desired state with continuous reconciliation. Argo CD and Flux are common choices.
Answer: Interfaces such as portals, APIs, CLIs and templates. The white paper describes interfaces separately from capabilities.
Answer: Self-service only works if users can discover and understand capabilities without asking. Docs and templates are part of the product.
Answer: The recommended, supported way to build and run a common type of service. Teams can step off it when they have good reasons.
Answer: Building capabilities nobody asked for without user research. Platforms must be user-driven.
Answer: By offering shared, reusable capabilities instead of every team building its own. e.g. one standard observability stack.
Answer: Defining platform infrastructure reproducibly in versioned code. Crossplane, Terraform/OpenTofu and Pulumi are common tools.
Answer: Several teams safely sharing platform infrastructure with isolation and fair resource use. Namespaces, quotas, RBAC and policies provide soft multi-tenancy.
Answer: Stages of platform maturity across aspects like investment, adoption, interfaces, operations and measurement. Published by the CNCF TAG App Delivery.
Answer: Consistency, speed and fewer human errors at scale. Automation encodes the golden path.
Answer: Treating developers as customers with a roadmap, feedback and product management. A product mindset keeps the platform relevant.
Answer: Teams get secure-by-default setups without each becoming security experts. Guardrails built into the defaults, rather than gates that each team must pass manually.
Answer: A short-lived environment created per change (e.g. per pull request) for testing. Platforms automate creating and destroying them.
Answer: Committing declarative requests (e.g. custom resources) that a controller fulfils. GitOps doubles as a self-service interface.
Answer: The platform is the capabilities; the portal is one interface to them. Backstage is a portal, not a platform by itself.
Answer: Latency; Traffic; Errors; Saturation. The four golden signals come from Google’s SRE book, chapter Monitoring Distributed Systems.
Answer: One vendor-neutral way to instrument, so backends can change without code changes. Collectors can route data to any backend.
Answer: Distributed traces. Traces show per-hop timing.
Answer: Understanding scheduling, image pull and probe problems on resources. Events are short-lived; export them if you need history.
Answer: mTLS with workload identities plus authorization policies. Istio and Linkerd are common meshes.
Answer: Kyverno; OPA Gatekeeper. They block non-compliant resources before they are stored.
Answer: Rules expressed as versioned code and evaluated automatically. Policies can run in CI and at admission.
Answer: RBAC scoped to their namespaces; Pod Security Standards; NetworkPolicies. Secure defaults reduce per-team mistakes.
Answer: A secret manager with short-lived, scoped credentials. Workload identity federation avoids long-lived keys.
Answer: Verifying at deploy time that images came from the trusted pipeline. Sigstore cosign plus admission verification.
Answer: Listing every component in an artifact so new vulnerabilities can be traced. Generated by tools like Syft or Trivy.
Answer: Resources and workloads continuously meet defined standards (security, compliance, configuration). Policy reports and scanners provide evidence.
Answer: Least-privilege, short-lived deploy credentials (or pull-based GitOps). Pipelines are high-value targets.
Answer: Alert on user-facing symptoms with SLOs; route causes to dashboards. Symptom-based, SLO-driven pages are actionable and reduce alert fatigue.
Answer: Consistent search, retention and correlation across services. Use structured logs with trace IDs.
Answer: Ownership and cost attribution across the platform. Required metadata makes governance possible.
Answer: Build, test, scan, then publish an image (and update desired state). Deployment is then handled by CD/GitOps.
Answer: CI produces verified artifacts; CD reconciles environments to desired state. Separating them limits credentials and blast radius.
Answer: By updating production’s desired state (e.g. a PR promoting the same image tag). Promote the same artifact.
Answer: Mitigate user impact (often by rolling back), then investigate. Restore service first; root-cause analysis and the postmortem come after.
Answer: An incident review focused on system and process improvements, not individuals. It encourages honest reporting.
Answer: Rollbacks are commits, and every change is visible in history. Revert the bad commit and the agent reconciles.
Answer: One directory or overlay per environment, with changes promoted by pull requests. Environment folders keep differences visible.
Answer: Clusters need no inbound access from the CI system. The agent pulls from inside the cluster.
Answer: Tekton. Argo Workflows is another Kubernetes-native option.
Answer: Releasing gradually (canary, blue-green, flags) with automated analysis and rollback. Argo Rollouts and Flagger implement it.
Answer: Versioned, reviewable and reproducible pipelines. Pipeline changes go through review like code.
Answer: Automatic rollback to the stable version. Analysis gates protect users.
Answer: A small, validated schema; Status conditions that report progress. Hide provider details behind a simple contract.
Answer: The operator pattern. Operators encode operational knowledge.
Answer: Through composite resources defined by an XRD and implemented by a Composition. Providers talk to cloud APIs.
Answer: Controllers keep working toward the declared state, repairing drift. Eventual consistency via level-triggered loops.
Answer: One consistent API, RBAC, GitOps and tooling for both apps and infrastructure. Teams reuse the same workflow for everything.
Answer: Machine-readable progress and health (e.g. Ready=True). Tools and humans rely on it to know when something is usable.
Answer: Versioned API versions with conversion, deprecations announced in advance. Kubernetes CRDs support multiple versions and conversion webhooks.
Answer: It installs managed resource types and controllers for an external API (e.g. AWS). Managed resources map 1:1 to external resources.
Answer: Teams get permission to create the high-level custom resources, not the underlying cloud resources. Self-service within guardrails.
Answer: Apply a short manifest (or fill a template) and get a ready database with credentials in a Secret. This is what platform APIs are for.
Answer: A controller that watches and acts on the custom resources. A CRD alone is just an API schema.
Answer: A user interface (e.g. Backstage) to discover and use platform capabilities, docs and ownership data. A portal sits on top of the platform.
Answer: Discoverable services and capabilities with owners, docs and request APIs. APIs make catalog data usable by automation too.
Answer: They create new services pre-wired with the golden path (CI, observability, docs). Backstage Software Templates are a common implementation.
Answer: Developer satisfaction surveys combined with flow metrics (e.g. time to first deploy). Mix qualitative and quantitative signals.
Answer: Assisting developers with platform docs and templates; Detecting anomalies in telemetry. AI works best on top of good APIs, catalogs and telemetry.
Answer: Self-service: templates, docs and access available without tickets. Time-to-first-commit/deploy is a common onboarding metric.
Answer: Different users and automation prefer different ways to consume the same capabilities. All interfaces should drive the same underlying APIs.
Answer: Change lead time; Deployment frequency; Failed deployment recovery time. Change fail rate and deployment rework rate measure instability.
Answer: The share of deployments that need immediate intervention (rollback or hotfix). It is an instability metric.
Answer: The share of deployments that are unplanned and happen because of a production incident. Added in DORA’s five-metric model.
Answer: Satisfaction, Performance, Activity, Communication & collaboration, Efficiency & flow. It argues productivity is multidimensional.
Answer: Share of services onboarded to the platform’s golden path. Adoption shows whether the platform is valued.
Answer: Delivery metrics show outcomes; surveys explain friction and satisfaction behind them. Quantitative and qualitative together tell the full story.
Answer: Commits per developer. Activity counts are easy to game and ignore quality.
Answer: Reduce cognitive load for app teams with self-service, product-minded capabilities. Platforms enable teams to deliver faster by abstracting common infrastructure concerns.
Answer: An opinionated, supported, well-documented way to accomplish a common task. Golden paths are paved roads — recommended and easy, but not a cage.
Answer: Understanding developer needs, iterating on feedback and measuring adoption. Developers are the customers; their adoption is the measure of success.
Answer: Kyverno; OPA Gatekeeper. Both run as admission webhooks evaluating policies on every request.
Answer: A service mesh with mTLS by default. Meshes handle identity and encryption transparently for every workload.
Answer: Apply manifests to production clusters with cluster credentials. The in-cluster GitOps agent deploys; CI updates desired state instead.
Answer: Revert the commit and let the agent reconcile. The revert restores known-good desired state and keeps Git the source of truth.
Answer: A CRD (or Crossplane composite resource) with a controller that provisions it. Custom resources plus controllers turn infrastructure into a self-service API.
Answer: Controllers continuously reconcile actual state toward desired state. The reconciliation loop repairs drift without human action.
Answer: The portal is one interface to the platform (alongside APIs, CLIs and Git). Backstage-style portals surface platform capabilities; the capabilities themselves live behind APIs.
Answer: Deployment frequency; Change lead time; Change fail rate; Deployment rework rate. DORA’s current model has five: change lead time, deployment frequency and failed deployment recovery time (throughput), plus change fail rate and deployment rework rate (instability). Activity counts are not among them.
Answer: Productivity is multidimensional (SPACE) and activity counts are easy to game. SPACE combines satisfaction, performance, activity, communication and efficiency.