Measure your Kubernetes administration readiness with 20 independent challenges that present a second set of operational scenarios across the public CKA domains. You work from cluster symptoms, request files, events, logs, and object state, then make the required changes and satisfy automated final-state checks without a command-by-command walkthrough.
This set emphasizes storage lifecycle, node and component troubleshooting, autoscaling and disruption controls, cluster extension interfaces, and newer networking primitives. It is a separate full-length practice form rather than a continuation of Practice Exam 01, and it assumes you already know the Kubernetes fundamentals being assessed.
What You Will Learn
- Dynamically provision log storage and safely rebind a released Retain-policy volume without losing its data
- Repair a static Pod, a cached-image pull path, metrics-server discovery, init container startup, node scheduling drift, and headless Service DNS
- Configure CPU-based Horizontal Pod Autoscaling and protect voluntary disruption with a PodDisruptionBudget
- Satisfy Restricted PodSecurity with non-root execution, seccomp, dropped capabilities, and explicit resource controls
- Delegate read-only cluster diagnostics with RBAC while denying mutation, Secret access, and wildcard administration
- Inspect and renew a staged kubeadm certificate, record node-drain evidence, and restore the node and workloads after upgrade preparation
- Customize a staged CSI-style package with Kustomize and verify an operator-reconciled custom resource
- Build Gateway API routing, repair EndpointSlice-backed Service access, restrict egress with NetworkPolicy, and add CoreDNS conditional forwarding
Who This Course Is For
This practice exam is for Kubernetes administrators and CKA candidates who have completed structured training and want another independent readiness check with different failure modes and resources. It suits learners who can investigate unfamiliar cluster state and choose their own valid command or YAML path.
Prerequisites: You should already be comfortable with Linux CLI work, Kubernetes YAML, kubectl, Pods, Deployments, StatefulSets, Services, storage, scheduling, RBAC, and troubleshooting. Prior exposure to HPA, PDB, Pod Security, kubeadm certificates, Kustomize, CRDs and controllers, Gateway API, EndpointSlices, NetworkPolicy, and CoreDNS is strongly recommended.
Learning environment: The course contains 20 separate challenge labs in an Ubuntu 22.04 CKA terminal environment with the labex-v135 single-node Kubernetes profile. Eleven challenges are labeled Intermediate and nine Advanced. Each starts in its own prepared VM, provides a situation, scope, acceptance criteria, and limited hints, and uses two or three automated checks to validate the required cluster or file state.
Frequently Asked Questions
Is this an official CKA exam or official question set?
No. This is an independent LabEx learning resource and is not affiliated with, endorsed by, or sponsored by The Linux Foundation or CNCF. Its coverage is informed by public CKA domains, but the tasks and their distribution do not represent the real exam’s questions or exact task mix.
How does this differ from CKA Practice Exam 01?
It is a separate full-length form, not a continuation, remediation set, or intentionally harder version. It rotates the scenarios and primitives: this set foregrounds dynamic storage and Retain recovery, static Pods, metrics infrastructure, HPA and PDB, Pod Security, Gateway API, egress policy, EndpointSlices, certificate inspection, and staged extension components.
How are time and scoring handled?
The recommended full attempt is 120 minutes. Each of the 20 challenges is worth 5 simulated points for a total of 100, and 66 points is the LabEx simulated practice threshold. These values are for self-assessment only and neither predict nor constitute an official CKA result.
Which infrastructure tasks are simulated or staged?
The certificate task renews only a staged kubeadm PKI copy, not the live cluster certificate. The upgrade task covers cordon, drain, evidence, uncordon, and workload recovery without installing binaries. The CSI task deploys a staged mock driver, while the operator and Gateway tasks use lightweight prepared components. These bounded exercises assess object and workflow skills, not full production lifecycle operations.


