CKAD sample questions with answers
10 free CKAD sample questions across the exam's domains, each with its answer and an explanation. No account needed.
CKAD sample questions
Certified Kubernetes Application Developer (CKAD), CNCF / The Linux Foundation.
Question 1
Domain: Application Design and Build
A Go service is built from a Dockerfile that uses a 900 MB SDK base image, and the resulting image ships the whole toolchain alongside a 20 MB binary.
Which Dockerfile change produces the smallest final image while still compiling inside the build?
- Add a final RUN step in the same stage that deletes the SDK and build cache after compiling
- List the SDK directories in .dockerignore so that they are excluded from the final image
- Replace every COPY instruction with ADD so that the layers are stored compressed
- Compile in an SDK-based first stage, then COPY --from that stage only the binary into a minimal final stage
Show the answer
Answer: D. Compile in an SDK-based first stage, then COPY --from that stage only the binary into a minimal final stage
A multi-stage build leaves the toolchain in an intermediate stage and copies only the artefacts into the final stage, so the SDK never reaches the shipped image. Deleting the SDK in a later RUN step is tempting, but the files still exist in the earlier layers, so the image does not shrink.
Checked against: https://docs.docker.com/build/building/multi-stage/
Question 2
Domain: Application Design and Build
A backup must run every day at 02:30. If the previous run is still going, the new run must be skipped rather than interrupting the running one.
Which CronJob spec meets the requirement?
- schedule: "30 2 * * *" with concurrencyPolicy: Forbid
- schedule: "30 2 * * *" with concurrencyPolicy: Replace
- schedule: "2 30 * * *" with concurrencyPolicy: Forbid
- schedule: "30 2 * * *" with concurrencyPolicy: Allow and parallelism: 1
Show the answer
Answer: A. schedule: "30 2 * * *" with concurrencyPolicy: Forbid
Cron fields are minute then hour, so 30 2 means 02:30, and Forbid skips a new run while the previous Job is still active. Replace is tempting because it also prevents overlap, but it does so by cancelling the running Job, which the requirement rules out.
Checked against: https://kubernetes.io/docs/concepts/workloads/controllers/cron-jobs/#concurrency-policy
Question 3
Domain: Application Deployment
Minutes after switching Service web from version: blue to version: green, error rates spike. The web-blue Deployment has not been scaled down.
What is the fastest safe way to roll back?
- Point the Service selector back to version: blue, which is still running
- Run kubectl rollout undo deployment/web-green
- Delete the green Pods so that the ReplicaSet recreates them from blue
- Change the image of web-green to the blue image and wait for the rollout
Show the answer
Answer: A. Point the Service selector back to version: blue, which is still running
Keeping the blue Deployment running is what makes blue/green rollback instant: you only repoint the Service selector. rollout undo is tempting, but it changes the green Deployment's own Pod template and leaves the Service pointing at green while new Pods roll out.
Checked against: https://kubernetes.io/docs/concepts/services-networking/service/#defining-a-service
Question 4
Domain: Application Deployment
A service takes an exclusive schema lock on start-up and crashes if two versions of it run at once. Brief downtime during upgrades is acceptable.
Which Deployment strategy guarantees that old and new versions never run at the same time?
- strategy.type: RollingUpdate with maxSurge: 0 and maxUnavailable: 1
- strategy.type: Recreate
- strategy.type: RollingUpdate with maxUnavailable: 0
- strategy.type: RollingUpdate with minReadySeconds: 0
Show the answer
Answer: B. strategy.type: Recreate
Recreate terminates all existing Pods before creating any new ones, so versions never overlap, at the cost of downtime. maxSurge: 0 is tempting, but a rolling update still replaces Pods one at a time, so old and new Pods run side by side during the rollout.
Checked against: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#recreate-deployment
Question 5
Domain: Application Observability and Maintenance
kubectl logs api-5d8 reports that a container name must be specified; the Pod has containers app and proxy.
Which command shows the proxy container's logs?
- kubectl logs api-5d8/proxy
- kubectl logs api-5d8 --name proxy
- kubectl exec api-5d8 -- logs proxy
- kubectl logs api-5d8 -c proxy
Show the answer
Answer: D. kubectl logs api-5d8 -c proxy
In a multi-container Pod you choose the container with -c (--container), or use --all-containers to see every one. The pod/container form is tempting, but kubectl logs does not accept that syntax for container names.
Checked against: https://kubernetes.io/docs/reference/kubectl/generated/kubectl_logs/
Question 6
Domain: Application Observability and Maintenance
livenessProbe: {httpGet: {path: /healthz, port: 8080}, periodSeconds: 5, timeoutSeconds: 1, failureThreshold: 4}
Roughly how long after the app hangs will the kubelet restart the container?
- About 20 seconds
- About 5 seconds
- About 4 seconds
- About 60 seconds
Show the answer
Answer: A. About 20 seconds
The container is restarted after failureThreshold consecutive failures, and probes run every periodSeconds, so 4 failures x 5 seconds is about 20 seconds. Five seconds is the tempting answer, but a single failed probe is not enough when failureThreshold is 4.
Checked against: https://kubernetes.io/docs/concepts/configuration/liveness-readiness-startup-probes/#configure-probes
Question 7
Domain: Application Environment, Configuration and Security
What does resources.requests.cpu: 250m mean?
- 250 megahertz of processor speed
- A quarter of one CPU core
- 250 MB of CPU cache
- 250 milliseconds of CPU time per minute
Show the answer
Answer: B. A quarter of one CPU core
CPU is measured in cores, and the m suffix means thousandths, so 250m is 0.25 CPU. Reading m as megabytes or megahertz is the tempting confusion; memory quantities use suffixes such as Mi or M instead.
Checked against: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu
Question 8
Domain: Application Environment, Configuration and Security
Pods fail with ErrImagePull because registry.example.com requires authentication.
What lets the Pods pull the image?
- Mount an Opaque Secret containing the password at /root/.docker in the container
- Put the registry password in an environment variable called REGISTRY_PASSWORD
- A docker-registry Secret listed under imagePullSecrets in the Pod spec
- Set imagePullPolicy: IfNotPresent so that the kubelet skips authentication
Show the answer
Answer: C. A docker-registry Secret listed under imagePullSecrets in the Pod spec
Image pulls are done by the kubelet before the container exists, so credentials must come from imagePullSecrets (directly or through the ServiceAccount). Mounting credentials into the container is tempting, but the container cannot start until the image has been pulled.
Checked against: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
Question 9
Domain: Services and Networking
Which NetworkPolicy denies all incoming traffic to every Pod in its namespace?
- podSelector: {} with policyTypes: [Ingress] and ingress: [{}]
- podSelector: {matchLabels: {deny: all}} with policyTypes: [Ingress]
- podSelector: {} with policyTypes: [Egress] and no egress rules
- podSelector: {} with policyTypes: [Ingress] and no ingress rules
Show the answer
Answer: D. podSelector: {} with policyTypes: [Ingress] and no ingress rules
An empty podSelector selects every Pod in the namespace, and listing Ingress with no ingress rules allows nothing in. ingress: [{}] is the tempting near-miss, but an empty rule matches all sources, so it allows all incoming traffic instead.
Checked against: https://kubernetes.io/docs/concepts/services-networking/network-policies/#default-deny-all-ingress-traffic
Question 10
Domain: Services and Networking
A NetworkPolicy's ingress rule contains: from: [ {namespaceSelector: {matchLabels: {team: a}}}, {podSelector: {matchLabels: {role: client}}} ] — two separate list items.
Which sources may reach the selected Pods?
- Only Pods labelled role: client that are in namespaces labelled team: a
- Only Pods labelled role: client in the policy's own namespace
- Pods in namespaces labelled team: a, or role: client Pods in its own namespace
- No sources, because namespaceSelector and podSelector cannot be combined
Show the answer
Answer: C. Pods in namespaces labelled team: a, or role: client Pods in its own namespace
Each list item under from is a separate peer and peers are ORed, so a namespaceSelector item and a podSelector item allow either source. The AND reading is the tempting one, but that requires both selectors in the same list item, without a second dash.
Checked against: https://kubernetes.io/docs/concepts/services-networking/network-policies/#behavior-of-to-and-from-selectors
More practice
A 20-question practice sampler is free with an account; Pro adds the full question bank and timed mock exams.
CKAD course and practice exam: Certified Kubernetes Application Developer: the exam guide, with the format, cost, pass mark and domains from the vendor.