KubeRusted
Spinning up your cluster…

CNPA exam prep — Certified Cloud Native Platform Engineering Associate

Free CNPA (Certified Cloud Native Platform Engineering Associate) practice: the 6 official domains, exam-style questions, a timed practice exam and more.

Play the CNPA map → · Official CNPA exam page

Platform Engineering Core Fundamentals (36%)

Declarative management, DevOps, environments, platform architecture, goals, CI, CD and GitOps

Platform Observability, Security, and Conformance (20%)

Traces/metrics/logs/events, secure service communication, policy engines, K8s and CI/CD security

Continuous Delivery & Platform Engineering (16%)

CI pipelines, incident response, CI/CD relationship, GitOps workflows and environments

Platform APIs and Provisioning Infrastructure (12%)

Reconciliation loop, CRDs as self-service APIs, infrastructure provisioning, operators

IDPs and Developer Experience (8%)

Simplified access, API-driven service catalogs, developer portals, AI/ML in automation

Measuring your Platform (8%)

Platform efficiency, team productivity, DORA metrics

Practice questions

According to the CNCF Platforms white paper, what is a platform?

Answer: An integrated collection of capabilities defined and presented according to the needs of its users. Capabilities are offered consistently, with interfaces and documentation.

Who are the primary users of an internal developer platform?

Answer: Application and product teams inside the organization. The platform team builds for internal developers as its customers.

Which is a platform capability example?

Answer: Provisioning databases on demand; Observability for every service; CI/CD pipelines. Capabilities are reusable building blocks app teams consume.

What does "thinnest viable platform" mean?

Answer: Start with the smallest set of capabilities that delivers value, then grow it. A wiki page of standards can be a first platform.

Why should platform adoption usually be optional rather than mandated?

Answer: Optional platforms must earn users by being better, which keeps the team user-focused. Mandates hide whether the platform actually helps.

What is a platform team’s relationship to app teams in Team Topologies terms?

Answer: Providing X-as-a-Service to stream-aligned teams. Enabling teams help others adopt new practices for a while.

What is the main problem platform engineering addresses?

Answer: Too much cognitive load and duplicated infrastructure work in app teams. Consistent self-service capabilities reduce both.

What distinguishes platform engineering from a traditional ops team handling tickets?

Answer: Self-service APIs and products instead of manual request queues. Platform as a product: capabilities are consumed on demand through interfaces, not requested through queues.

What is declarative resource management?

Answer: Describing desired state and letting controllers converge actual state to it. The Kubernetes API model.

Why do platforms prefer declarative over imperative interfaces?

Answer: Declared state can be versioned, reviewed, reconciled and recreated. Drift is detectable when desired state is declared.

What are "application environments" in platform terms?

Answer: Consistent, reproducible places (dev, staging, prod) to run and promote applications. Platforms often offer ephemeral preview environments too.

Which DevOps practice does platform engineering build on?

Answer: Automation and shared ownership of delivery. Platforms scale DevOps practices across many teams.

What is continuous integration?

Answer: Merging changes frequently with automated builds and tests. Fast feedback on every change.

What is continuous delivery?

Answer: Keeping software always releasable, delivering through automated pipelines. GitOps is one implementation of CD.

What is the role of GitOps in a platform?

Answer: Delivering apps and platform config from versioned desired state with continuous reconciliation. Argo CD and Flux are common choices.

Which platform architecture layer exposes capabilities to users?

Answer: Interfaces such as portals, APIs, CLIs and templates. The white paper describes interfaces separately from capabilities.

Why document platform capabilities well?

Answer: Self-service only works if users can discover and understand capabilities without asking. Docs and templates are part of the product.

What is a "paved road" or golden path?

Answer: The recommended, supported way to build and run a common type of service. Teams can step off it when they have good reasons.

Which is a common platform engineering anti-pattern?

Answer: Building capabilities nobody asked for without user research. Platforms must be user-driven.

How does a platform reduce duplicated effort?

Answer: By offering shared, reusable capabilities instead of every team building its own. e.g. one standard observability stack.

What is infrastructure as code’s role in platforms?

Answer: Defining platform infrastructure reproducibly in versioned code. Crossplane, Terraform/OpenTofu and Pulumi are common tools.

What is multi-tenancy in a platform context?

Answer: Several teams safely sharing platform infrastructure with isolation and fair resource use. Namespaces, quotas, RBAC and policies provide soft multi-tenancy.

What does the Platform Engineering Maturity Model describe?

Answer: Stages of platform maturity across aspects like investment, adoption, interfaces, operations and measurement. Published by the CNCF TAG App Delivery.

Why do platforms favour automation over manual operations?

Answer: Consistency, speed and fewer human errors at scale. Automation encodes the golden path.

What is "platform as a product" mainly about?

Answer: Treating developers as customers with a roadmap, feedback and product management. A product mindset keeps the platform relevant.

Why include security and compliance in platform defaults?

Answer: Teams get secure-by-default setups without each becoming security experts. Guardrails built into the defaults, rather than gates that each team must pass manually.

What is an ephemeral environment?

Answer: A short-lived environment created per change (e.g. per pull request) for testing. Platforms automate creating and destroying them.

Which interface lets developers consume platform capabilities through Git?

Answer: Committing declarative requests (e.g. custom resources) that a controller fulfils. GitOps doubles as a self-service interface.

What is the difference between a platform and a portal?

Answer: The platform is the capabilities; the portal is one interface to them. Backstage is a portal, not a platform by itself.

What are the four golden signals of monitoring?

Answer: Latency; Traffic; Errors; Saturation. The four golden signals come from Google’s SRE book, chapter Monitoring Distributed Systems.

Why standardize on OpenTelemetry in a platform?

Answer: One vendor-neutral way to instrument, so backends can change without code changes. Collectors can route data to any backend.

Which signal helps find which service in a call chain is slow?

Answer: Distributed traces. Traces show per-hop timing.

What are Kubernetes Events useful for in platform observability?

Answer: Understanding scheduling, image pull and probe problems on resources. Events are short-lived; export them if you need history.

How does a service mesh secure service-to-service communication?

Answer: mTLS with workload identities plus authorization policies. Istio and Linkerd are common meshes.

Which policy engines enforce platform guardrails at Kubernetes admission?

Answer: Kyverno; OPA Gatekeeper. They block non-compliant resources before they are stored.

What is "policy as code"?

Answer: Rules expressed as versioned code and evaluated automatically. Policies can run in CI and at admission.

Which Kubernetes security essentials should every tenant get by default?

Answer: RBAC scoped to their namespaces; Pod Security Standards; NetworkPolicies. Secure defaults reduce per-team mistakes.

Where should secrets used by pipelines come from?

Answer: A secret manager with short-lived, scoped credentials. Workload identity federation avoids long-lived keys.

What does signing artifacts in CI enable?

Answer: Verifying at deploy time that images came from the trusted pipeline. Sigstore cosign plus admission verification.

What is an SBOM used for in CI/CD security?

Answer: Listing every component in an artifact so new vulnerabilities can be traced. Generated by tools like Syft or Trivy.

What does "conformance" mean for a platform?

Answer: Resources and workloads continuously meet defined standards (security, compliance, configuration). Policy reports and scanners provide evidence.

Which control limits the blast radius of a compromised CI pipeline?

Answer: Least-privilege, short-lived deploy credentials (or pull-based GitOps). Pipelines are high-value targets.

Which is a good alerting practice for a platform?

Answer: Alert on user-facing symptoms with SLOs; route causes to dashboards. Symptom-based, SLO-driven pages are actionable and reduce alert fatigue.

Why centralize logs from all platform tenants?

Answer: Consistent search, retention and correlation across services. Use structured logs with trace IDs.

What is the purpose of admission policies that require labels like team and cost-center?

Answer: Ownership and cost attribution across the platform. Required metadata makes governance possible.

What does a typical CI pipeline do for a containerized service?

Answer: Build, test, scan, then publish an image (and update desired state). Deployment is then handled by CD/GitOps.

What separates CI from CD in a GitOps platform?

Answer: CI produces verified artifacts; CD reconciles environments to desired state. Separating them limits credentials and blast radius.

How should a change move from staging to production in GitOps?

Answer: By updating production’s desired state (e.g. a PR promoting the same image tag). Promote the same artifact.

What is the first priority in incident response?

Answer: Mitigate user impact (often by rolling back), then investigate. Restore service first; root-cause analysis and the postmortem come after.

What is a blameless postmortem?

Answer: An incident review focused on system and process improvements, not individuals. It encourages honest reporting.

How does GitOps help incident response?

Answer: Rollbacks are commits, and every change is visible in history. Revert the bad commit and the agent reconciles.

What is a GitOps environment-promotion pattern?

Answer: One directory or overlay per environment, with changes promoted by pull requests. Environment folders keep differences visible.

Which is an advantage of pull-based GitOps delivery?

Answer: Clusters need no inbound access from the CI system. The agent pulls from inside the cluster.

Which tool is Kubernetes-native CI with Task and Pipeline resources?

Answer: Tekton. Argo Workflows is another Kubernetes-native option.

What is progressive delivery?

Answer: Releasing gradually (canary, blue-green, flags) with automated analysis and rollback. Argo Rollouts and Flagger implement it.

Why keep pipelines as code in the repository?

Answer: Versioned, reviewable and reproducible pipelines. Pipeline changes go through review like code.

What should happen when a deployment’s health checks fail during a progressive rollout?

Answer: Automatic rollback to the stable version. Analysis gates protect users.

What makes a CRD a good platform API?

Answer: A small, validated schema; Status conditions that report progress. Hide provider details behind a simple contract.

Which Kubernetes extension pattern pairs a CRD with a controller that manages an application’s lifecycle?

Answer: The operator pattern. Operators encode operational knowledge.

How does Crossplane let teams request cloud resources?

Answer: Through composite resources defined by an XRD and implemented by a Composition. Providers talk to cloud APIs.

What does the Kubernetes reconciliation loop guarantee for platform APIs?

Answer: Controllers keep working toward the declared state, repairing drift. Eventual consistency via level-triggered loops.

Why expose infrastructure through Kubernetes APIs at all?

Answer: One consistent API, RBAC, GitOps and tooling for both apps and infrastructure. Teams reuse the same workflow for everything.

What does status.conditions on a custom resource communicate?

Answer: Machine-readable progress and health (e.g. Ready=True). Tools and humans rely on it to know when something is usable.

How should a platform API change without breaking users?

Answer: Versioned API versions with conversion, deprecations announced in advance. Kubernetes CRDs support multiple versions and conversion webhooks.

What is the role of a provider in Crossplane?

Answer: It installs managed resource types and controllers for an external API (e.g. AWS). Managed resources map 1:1 to external resources.

How do RBAC and platform APIs work together?

Answer: Teams get permission to create the high-level custom resources, not the underlying cloud resources. Self-service within guardrails.

What is an ideal "request a database" experience for a developer?

Answer: Apply a short manifest (or fill a template) and get a ready database with credentials in a Secret. This is what platform APIs are for.

Which component must exist for a CRD to do anything beyond storing data?

Answer: A controller that watches and acts on the custom resources. A CRD alone is just an API schema.

What is an internal developer portal?

Answer: A user interface (e.g. Backstage) to discover and use platform capabilities, docs and ownership data. A portal sits on top of the platform.

What does an API-driven service catalog provide?

Answer: Discoverable services and capabilities with owners, docs and request APIs. APIs make catalog data usable by automation too.

How do software templates help developer experience?

Answer: They create new services pre-wired with the golden path (CI, observability, docs). Backstage Software Templates are a common implementation.

What is a good measure of developer experience improvements?

Answer: Developer satisfaction surveys combined with flow metrics (e.g. time to first deploy). Mix qualitative and quantitative signals.

Where can AI help in platform engineering?

Answer: Assisting developers with platform docs and templates; Detecting anomalies in telemetry. AI works best on top of good APIs, catalogs and telemetry.

What reduces onboarding time for a new developer most?

Answer: Self-service: templates, docs and access available without tickets. Time-to-first-commit/deploy is a common onboarding metric.

Why should a platform offer several interfaces (portal, CLI, API, GitOps)?

Answer: Different users and automation prefer different ways to consume the same capabilities. All interfaces should drive the same underlying APIs.

Which DORA metrics measure software delivery throughput?

Answer: Change lead time; Deployment frequency; Failed deployment recovery time. Change fail rate and deployment rework rate measure instability.

What does change fail rate measure?

Answer: The share of deployments that need immediate intervention (rollback or hotfix). It is an instability metric.

What is deployment rework rate?

Answer: The share of deployments that are unplanned and happen because of a production incident. Added in DORA’s five-metric model.

What does the SPACE framework stand for?

Answer: Satisfaction, Performance, Activity, Communication & collaboration, Efficiency & flow. It argues productivity is multidimensional.

Which is a platform adoption metric?

Answer: Share of services onboarded to the platform’s golden path. Adoption shows whether the platform is valued.

Why combine DORA metrics with developer surveys?

Answer: Delivery metrics show outcomes; surveys explain friction and satisfaction behind them. Quantitative and qualitative together tell the full story.

Which is a poor single productivity metric?

Answer: Commits per developer. Activity counts are easy to game and ignore quality.

What is the primary goal of platform engineering?

Answer: Reduce cognitive load for app teams with self-service, product-minded capabilities. Platforms enable teams to deliver faster by abstracting common infrastructure concerns.

A "golden path" is best described as…

Answer: An opinionated, supported, well-documented way to accomplish a common task. Golden paths are paved roads — recommended and easy, but not a cage.

Treating the platform as a product means…

Answer: Understanding developer needs, iterating on feedback and measuring adoption. Developers are the customers; their adoption is the measure of success.

Which tools enforce policy as code at Kubernetes admission?

Answer: Kyverno; OPA Gatekeeper. Both run as admission webhooks evaluating policies on every request.

How do platforms usually provide encrypted, authenticated service-to-service traffic?

Answer: A service mesh with mTLS by default. Meshes handle identity and encryption transparently for every workload.

In a GitOps-based platform, what does CI typically NOT do?

Answer: Apply manifests to production clusters with cluster credentials. The in-cluster GitOps agent deploys; CI updates desired state instead.

Production breaks after a GitOps deploy. Fastest safe mitigation?

Answer: Revert the commit and let the agent reconcile. The revert restores known-good desired state and keeps Git the source of truth.

Teams should request a database by applying a small YAML file. What makes that possible?

Answer: A CRD (or Crossplane composite resource) with a controller that provisions it. Custom resources plus controllers turn infrastructure into a self-service API.

What makes Kubernetes-based platform APIs self-healing?

Answer: Controllers continuously reconcile actual state toward desired state. The reconciliation loop repairs drift without human action.

How does a developer portal relate to an internal developer platform?

Answer: The portal is one interface to the platform (alongside APIs, CLIs and Git). Backstage-style portals surface platform capabilities; the capabilities themselves live behind APIs.

Which of these are DORA software delivery performance metrics?

Answer: Deployment frequency; Change lead time; Change fail rate; Deployment rework rate. DORA’s current model has five: change lead time, deployment frequency and failed deployment recovery time (throughput), plus change fail rate and deployment rework rate (instability). Activity counts are not among them.

Why is "number of commits per developer" a poor productivity metric on its own?

Answer: Productivity is multidimensional (SPACE) and activity counts are easy to game. SPACE combines satisfaction, performance, activity, communication and efficiency.