All articles

How to Prepare for the CKAD Exam: A Study Plan That Works

What the Certified Kubernetes Application Developer exam looks like, which topics carry the most weight, the kubectl habits that save time, a six-week study plan, and the mistakes that make prepared candidates fail.

Training|Published |9 min read
Open book and handwritten notes on a desk in front of a bookshelf

The Certified Kubernetes Application Developer (CKAD) exam has no multiple choice questions. You get a terminal, a set of clusters, and around two hours to fix and build things with kubectl. People who know Kubernetes well still fail it because they run out of time. Passing comes down to two things: covering the curriculum, and being fast enough at the command line that you finish every task. This guide covers both.

What the Exam Looks Like

  • It is an online, proctored exam taken from your own computer in a locked-down browser that opens a remote desktop.
  • You have two hours for roughly 15 to 20 practical tasks, each worth a different number of points.
  • The passing score is 66 percent.
  • You can open the official Kubernetes documentation during the exam, but not personal notes or other websites.
  • The registration includes one free retake and access to an exam simulator from killer.sh.
  • A pass is valid for two years.

The Linux Foundation updates the exam and its rules from time to time, including the Kubernetes version it runs on. Read the current candidate handbook before you book a date.

The Curriculum and Where the Points Are

DomainWeightWhat it covers
Application Design and Build20%Container images, Jobs and CronJobs, multi-container Pods with sidecar and init containers, volumes
Application Deployment20%Deployments, rolling updates and rollbacks, blue-green and canary patterns, Helm, Kustomize
Application Observability and Maintenance15%Liveness, readiness, and startup probes, logs, debugging failing Pods, API deprecations
Application Environment, Configuration and Security25%ConfigMaps, Secrets, ServiceAccounts, SecurityContext, resource requests and limits, quotas, RBAC basics
Services and Networking20%Services, Ingress, and NetworkPolicies

Configuration and security is the largest domain, and NetworkPolicy tasks are the ones candidates most often get wrong. Spend extra practice time on both.

Speed Is a Skill You Have to Practise

Writing YAML from memory is slow and error prone. Generate it instead. Most objects can be created with an imperative command, and adding --dry-run=client -o yaml prints the manifest so you can save it, edit the few fields the command cannot set, and apply it.

  • Set alias k=kubectl and export do="--dry-run=client -o yaml" at the start, so k run web --image=nginx $do > pod.yaml is quick to type.
  • Use kubectl create for Deployments, Jobs, CronJobs, ConfigMaps, Secrets, ServiceAccounts, Roles, and RoleBindings, and kubectl expose for Services.
  • Use kubectl explain pod.spec.containers.livenessProbe to look up field names without leaving the terminal.
  • Learn enough vim to indent blocks, copy lines, and paste without breaking the indentation.
  • You cannot bring bookmarks, so learn where the NetworkPolicy, probe, and SecurityContext examples sit in the docs.

A Six-Week Study Plan

  1. 1Week 1: run a local cluster with kind or minikube and work through Pods, Deployments, Services, and kubectl basics until you no longer need to look up common commands.
  2. 2Week 2: configuration. ConfigMaps and Secrets as environment variables and as files, resource requests and limits, ServiceAccounts, and SecurityContext.
  3. 3Week 3: multi-container Pods, init containers, volumes, Jobs, and CronJobs.
  4. 4Week 4: probes, debugging Pods that crash or stay pending, rolling updates, rollbacks, Helm, and Kustomize.
  5. 5Week 5: Services, Ingress, and NetworkPolicies. Write policies until you can predict which traffic each one allows.
  6. 6Week 6: do the first killer.sh session under exam conditions, review every task you missed, practise those areas, then do the second session a few days before the exam.

The killer.sh simulator is intentionally harder and longer than the real exam. A low score there is normal. Use it to find gaps, then repeat the tasks until you can solve them without the documentation.

Mistakes That Cost a Pass

  • Working in the wrong cluster. Every task begins with a kubectl config use-context command. Copy and run it every single time.
  • Creating resources in the default namespace when the task names another one.
  • Spending fifteen minutes on a task worth two percent. Flag it, move on, and come back at the end.
  • Forgetting to verify. After each task, run kubectl get or describe to confirm the Pod is running and the fields are set.
  • Not reading the whole question. Tasks often ask for a specific file path, label, or container name, and the checker looks for exactly that.

Exam Day

Run the system check a day before, clear your desk, and have your ID ready. Check-in with the proctor can take a while, so start early. During the exam, go through the tasks in order, skip anything that looks long, and leave the last twenty minutes for the flagged ones.

CKAD rewards people who have used Kubernetes every day for a few weeks far more than people who have read about it for months.

If several engineers in your team are preparing, studying together with a trainer who sets daily lab tasks keeps everyone moving and catches bad habits early. Our CKAD training follows the same structure as the plan above, with hands-on labs on real clusters.

Key takeaways

  • CKAD is a two hour hands-on exam with a 66 percent passing score, and time pressure is the main reason people fail.
  • Configuration and security is the largest domain, and NetworkPolicies need extra practice.
  • Generate YAML with imperative commands and --dry-run=client -o yaml instead of writing it by hand.
  • Switch context at the start of every task and check the namespace.
  • Use the two killer.sh sessions to find gaps, and expect lower scores there than in the real exam.

Related articles

More articles on software development, AI, cloud, and infrastructure.

Hands sorting printed tax forms and receipts next to a calculator
AI Development|

Automating Document Data Entry With AI: Invoices, Receipts, and Forms

How AI reads invoices, receipts, ID cards, and forms and turns them into structured data, how OCR and large language models fit together, why validation and human review still matter, how to measure accuracy, and what to watch for with personal data.

Aerial view of a busy container port with cranes and stacked shipping containers
DevOps|

Deploying Applications to Kubernetes With Helm: A Practical Guide

What Helm charts are, how values and templates work, how to structure a chart for several environments, upgrade and rollback safely, keep secrets out of Git, test charts in CI, and decide between Helm and Kustomize.

Looking for a software development partner?

Tell us about your project, what you need to build, and the challenges you are facing. We can discuss the technical approach, scope, timeline, and estimated cost.

Start a conversation