Assess your Kubernetes application skills through 20 independent CKAD-style challenges built around a second set of deployment, configuration, security, observability, and networking scenarios. You investigate prepared resources and failure evidence, choose your own commands or YAML changes, and satisfy automated final-state checks without a guided walkthrough.
This exam form emphasizes indexed batch work, projected data, blue/green traffic switching, release rollback and upgrade, namespace resource defaults, tightly scoped application identity, and multi-path networking. It stands alone from Practice Exam 01 and assumes you already understand the Kubernetes application concepts being tested.
What You Will Learn
- Complete and load a local worker image, then run it behind a Service without publishing it to an external registry
- Run an Indexed parallel Job, build an adapter sidecar with shared
emptyDirdata, and combine projected sources with PVC storage - Switch a Service from blue to green, roll back a faulty Deployment, upgrade a local Helm release, and generate a Kustomize overlay
- Repair slow startup and readiness probes, diagnose a broken ConfigMap rollout, and migrate a deprecated PodDisruptionBudget manifest
- Project selected ConfigMap and Secret keys into files without exposing secret values
- Apply LimitRange defaults and ResourceQuota, then grant one ServiceAccount access to only a named ConfigMap
- Harden a writable-cache Pod under Restricted Pod Security and create a valid resource using a versioned CRD
- Repair named Service ports and DNS references, route two Ingress paths, and allow NetworkPolicy traffic from only one namespace and Pod set
Who This Course Is For
This practice exam is for application developers, platform engineers, and CKAD candidates who want another full readiness check with different scenarios from the first form. It suits learners who can inspect manifests, status, Events, logs, EndpointSlices, and authorization results without step-by-step commands.
Prerequisites: You should be comfortable with Linux CLI work, Kubernetes YAML, kubectl, Pods, Deployments, Jobs, ConfigMaps, Secrets, volumes, Services, labels, selectors, rollouts, and basic debugging. Familiarity with local image builds, probes, Helm, Kustomize, RBAC, LimitRange and ResourceQuota, CRDs, Ingress, NetworkPolicy, and security contexts is recommended.
Learning environment: The course contains 20 separate challenge labs in an Ubuntu 22.04 CKAD terminal environment with the single-node labex-v135 Kubernetes profile. Sixteen challenges are labeled Intermediate and four Advanced. Each starts in its own prepared VM, provides a scenario, scope, acceptance criteria, and limited hints, and uses two automated checks to validate the required application and cluster state.
Frequently Asked Questions
Is this an official CKAD exam or official question set?
No. This is an independent LabEx learning resource and is not affiliated with, endorsed by, or sponsored by The Linux Foundation or CNCF. Its coverage is informed by public CKAD domains, but the tasks and their distribution do not represent the real exam’s questions or exact task mix.
How does this differ from CKAD Practice Exam 01?
It is another complete exam form, not a sequel, remediation set, or intentionally harder level. This set rotates to an Indexed Job, adapter sidecar, projected volume, blue/green switch, rollback, Helm upgrade, LimitRange defaults, versioned CRD, split-path Ingress, cross-namespace policy, and Service DNS repair.
How are time and scoring handled?
The recommended full attempt is 120 minutes. Each of the 20 challenges is worth 5 simulated points for a total of 100, and 66 points is the LabEx simulated practice threshold. These values support self-assessment only and neither predict nor constitute an official CKAD result.
Do the packaging tasks require external artifact services?
No. The worker image is built locally and loaded into the prepared minikube profile, the Helm release uses a staged local chart, and the Kustomize base and overlay skeleton are in the workspace. The exam does not require you to push an image or fetch a remote chart dependency during learner work.


