Asterrr's Handbook

The KCNA exam

Format, domain weights, the competency numbering used in this handbook, and how to eliminate look-alike options.

Format

90 minutes
Online and proctored. About 1.5 minutes per question.
~60 questions
Multiple choice, one correct answer each.
75%
Passing score.
No prerequisite
The entry-level CNCF exam. It's a common first step before the CKA, CKAD or KCSA.
1 retake
A free retake is included.
2 years
Certification validity.

Where the points are

DomainWeightIn one sentence
1 · Kubernetes fundamentals44%What each component and object does, how you talk to the API, how Pods get scheduled, and how containers work
2 · Container orchestration28%How Pods talk to each other, how the cluster is secured, how storage attaches, and how you find out what broke
3 · Cloud native application delivery16%Getting code into a cluster safely: CI/CD, GitOps, Helm, release strategies, and debugging a running app
4 · Cloud native architecture12%Observability, the principles behind cloud native design, and the CNCF projects and community

Competency numbers

The curriculum lists competencies without numbers. This handbook numbers them in curriculum order, and each page's Exam tasks line uses these numbers.

DomainCompetencies
1 · Kubernetes fundamentals1.1 Kubernetes core concepts · 1.2 Administration · 1.3 Scheduling · 1.4 Containerization
2 · Container orchestration2.1 Networking · 2.2 Security · 2.3 Troubleshooting · 2.4 Storage
3 · Cloud native application delivery3.1 Application delivery · 3.2 Debugging
4 · Cloud native architecture4.1 Observability · 4.2 Cloud native ecosystem and principles · 4.3 Cloud native community and collaboration

How to read a KCNA question

Phrase in the questionWhat it usually points to
Stores cluster stateetcd, never the API server or the scheduler
Decides which nodekube-scheduler. The kubelet only runs what it's assigned
Runs on every nodekubelet and kube-proxy (components), or a DaemonSet (workload)
Stable identity / ordered startupStatefulSet
Runs to completionJob, or CronJob for a schedule
Git is the source of truthGitOps, with Argo CD or Flux
Graduated / incubating / sandboxCNCF project maturity levels

Exam signal

Many options are real Kubernetes words. Ask what each one actually does. "ReplicaSet", "Deployment" and "StatefulSet" all keep Pods running, but only one fits a question about rolling updates of a stateless app.

The most powerful option

Options like "give the Pod cluster-admin" or "run the container as privileged" fix the symptom in the question but break security principles the exam expects you to keep. Prefer the narrowest fix.

If your material is older

Older material saysUse now
Docker as the Kubernetes runtime (dockershim)containerd or CRI-O through the CRI. Docker-built images still run fine
PodSecurityPolicyPod Security Admission with the Pod Security Standards
OpenTracing, OpenCensusOpenTelemetry
Observability as its own exam domainPart of Cloud Native Architecture (4.1)
Scenario
Which component is responsible for picking the node a new Pod will run on?

Further reading

On this page