The KCNA exam
Format, domain weights, the competency numbering used in this handbook, and how to eliminate look-alike options.
Format
Where the points are
| Domain | Weight | In one sentence |
|---|---|---|
| 1 · Kubernetes fundamentals | 44% | What each component and object does, how you talk to the API, how Pods get scheduled, and how containers work |
| 2 · Container orchestration | 28% | How Pods talk to each other, how the cluster is secured, how storage attaches, and how you find out what broke |
| 3 · Cloud native application delivery | 16% | Getting code into a cluster safely: CI/CD, GitOps, Helm, release strategies, and debugging a running app |
| 4 · Cloud native architecture | 12% | Observability, the principles behind cloud native design, and the CNCF projects and community |
Competency numbers
The curriculum lists competencies without numbers. This handbook numbers them in curriculum order, and each page's Exam tasks line uses these numbers.
| Domain | Competencies |
|---|---|
| 1 · Kubernetes fundamentals | 1.1 Kubernetes core concepts · 1.2 Administration · 1.3 Scheduling · 1.4 Containerization |
| 2 · Container orchestration | 2.1 Networking · 2.2 Security · 2.3 Troubleshooting · 2.4 Storage |
| 3 · Cloud native application delivery | 3.1 Application delivery · 3.2 Debugging |
| 4 · Cloud native architecture | 4.1 Observability · 4.2 Cloud native ecosystem and principles · 4.3 Cloud native community and collaboration |
How to read a KCNA question
| Phrase in the question | What it usually points to |
|---|---|
| Stores cluster state | etcd, never the API server or the scheduler |
| Decides which node | kube-scheduler. The kubelet only runs what it's assigned |
| Runs on every node | kubelet and kube-proxy (components), or a DaemonSet (workload) |
| Stable identity / ordered startup | StatefulSet |
| Runs to completion | Job, or CronJob for a schedule |
| Git is the source of truth | GitOps, with Argo CD or Flux |
| Graduated / incubating / sandbox | CNCF project maturity levels |
Exam signal
Many options are real Kubernetes words. Ask what each one actually does. "ReplicaSet", "Deployment" and "StatefulSet" all keep Pods running, but only one fits a question about rolling updates of a stateless app.
The most powerful option
Options like "give the Pod cluster-admin" or "run the container as privileged" fix the symptom in the question but break security principles the exam expects you to keep. Prefer the narrowest fix.
If your material is older
| Older material says | Use now |
|---|---|
| Docker as the Kubernetes runtime (dockershim) | containerd or CRI-O through the CRI. Docker-built images still run fine |
| PodSecurityPolicy | Pod Security Admission with the Pod Security Standards |
| OpenTracing, OpenCensus | OpenTelemetry |
| Observability as its own exam domain | Part of Cloud Native Architecture (4.1) |
The scheduler filters nodes that can run the Pod and scores the rest, then writes the chosen node into the Pod's
spec.nodeName. The kubelet on that node then starts the containers. The controller manager creates Pods (for
example from a ReplicaSet) but doesn't place them, and kube-proxy handles Service traffic.
Further reading
How to use this handbook
Concept-first notes for the KCNA. Each page explains which Kubernetes piece or cloud native practice solves which problem.
Domain 1 · Kubernetes fundamentals
44% of the exam. What each cluster component and object does, how you talk to the API, how the scheduler places Pods, and how containers and runtimes fit underneath.