24 - Certification Exam Prep (CKA/CKAD/CKS)
Why this matters
Certification forces structured, timed, hands-on practice — no multiple choice, all
real kubectl/YAML under a clock. Even if you never need the cert for a job, prepping
for it is one of the fastest ways to close remaining gaps.
Read this first — Definitions & Explanations
CKA (Certified Kubernetes Administrator)
Focus: cluster operations — scheduling, networking, security basics, maintenance, troubleshooting under time pressure.
CKAD (Certified Kubernetes Application Developer)
Focus: building/deploying apps on Kubernetes — workloads, config, multi-container Pods, services, observability basics.
CKS (Certified Kubernetes Security Specialist)
Focus: hardening clusters and workloads — supply chain, runtime security, network policies, auditing, least privilege.
Exam reality
Speed comes from muscle memory + knowing how to use docs quickly — not from memorizing every YAML field once.
Prep loop that works
- Finish this path module-by-module with labs
- Redo weak topics
- Timed mock scenarios
- Review mistakes the same day
Recommended order
- CKA (Certified Kubernetes Administrator) — cluster admin, troubleshooting, covers most of Phases 1-2 of this path
- CKAD (Certified Kubernetes Application Developer) — faster to get after CKA, overlaps heavily, app-focused
- CKS (Certified Kubernetes Security Specialist) — requires an active CKA first, covers Phase 3 of this path
Official docs (read for detail)
- CKA Curriculum
- Kubernetes Documentation (home)
- kubectl Cheat Sheet
- API Overview
- Training & Certification (CNCF)
Key Concepts / Exam Mechanics
- Open-book: you get the official Kubernetes docs during the exam — practice navigating them FAST
- Time pressure is the real challenge, not the concepts — CKA is 2 hours, ~15-20 tasks across multiple clusters (via
kubectl config use-context) kubectlshortcuts are essential: aliases,--dry-run=client -o yaml, imperative commands to generate YAML fast- Practice environment: killer.sh (comes free with exam registration, 2 sessions) — closest thing to the real exam, harder than the actual test on purpose
YouTube search terms
- "CKA exam tips and tricks 2025/2026"
- "CKA exam simulator killer.sh walkthrough"
- "kubectl productivity tips for CKA exam"
- "CKS exam tips Kubernetes security certification"
Exam-day productivity setup (practice this now, not on exam day)
# Put this in your shell profile and drill until it's muscle memory
alias k=kubectl
export do="--dry-run=client -o yaml" # k run nginx --image=nginx $do > pod.yaml
export now="--force --grace-period=0" # k delete pod x $now
complete -o default -F __start_kubectl k
# Speed-generate YAML instead of writing from scratch
kubectl create deployment web --image=nginx --replicas=3 $do > deploy.yaml
kubectl expose deployment web --port=80 $do > svc.yaml
kubectl create job myjob --image=busybox $do -- echo hi > job.yaml
# Fast context switching (exam gives you multiple clusters)
kubectl config get-contexts
kubectl config use-context <name>
# vim setup for YAML editing (set this in exam terminal at the start)
# ~/.vimrc equivalent commands to run at exam start:
# set expandtab
# set shiftwidth=2
# set tabstop=2
Hands-on lab (on prod-sim)
- Do timed drills: pick 5 random topics from Phases 1-2, give yourself 90 seconds each
to solve blind (no notes) using only
kubectl+--help+ imperative generators - Practice the etcd backup/restore (topic 14) until you can do it in under 5 minutes
- Practice RBAC troubleshooting (topic 08) — "why can't this ServiceAccount do X" — blind
- Time yourself doing a full node drain+cordon+uncordon+taint cycle (topic 06/11)
Notes
(fill in your own words — track your mock exam scores here over time)