questions people ask about each exam — difficulty, cost, format, prerequisites, renewal, and how to pass.
It's the CNCF's entry-level, foundational certification for Kubernetes and the cloud-native ecosystem — Kubernetes fundamentals, container orchestration, cloud-native architecture, observability, and the CNCF project landscape. It's the conceptual on-ramp before the hands-on Kubernetes exams. It's a 60-question, 90-minute multiple-choice exam; see the KCNA hub for the full scope.
Multiple choice — this is the key difference from CKA/CKAD/CKS. KCNA is a knowledge exam (60 multiple-choice questions), not a performance-based one, so there's no live terminal or cluster work. It tests whether you understand Kubernetes and cloud-native concepts, which is why it works as a foundational credential.
It's the easiest Kubernetes certification — concept-level and passable in one to three weeks for most people, even without deep hands-on experience. The breadth of the CNCF landscape (projects, terminology) is the main thing to absorb. Practice questions are the quickest way to confirm you're ready.
It's closed-book and remotely proctored (through PSI) — unlike the hands-on CKA/CKAD/CKS exams, you cannot reference the Kubernetes documentation during KCNA. You take it online with a webcam and a clear workspace, and a proctor monitors the session.
60 multiple-choice questions in 90 minutes, with a passing score around 75%. The certification is valid for 2 years, after which you recertify by retaking the current exam. There's no penalty for wrong answers, so answer every question.
Yes, if you're starting with Kubernetes or need to prove cloud-native literacy — it's an affordable, recognized foundation and a natural stepping stone to CKA/CKAD. Experienced engineers often skip it and go straight to the hands-on exams. See how it compares on our State of Certifications report.
Around $250 USD, which includes one free retake — a nice safety net. Scheduling and system requirements for the online exam are on our Kubernetes exam info page.
Register through the Linux Foundation / CNCF training portal, then schedule your online proctored slot through PSI. Our Kubernetes exam info page covers registration, ID, and the workspace requirements for the remote exam.
Learn Kubernetes fundamentals and the CNCF landscape (the free Linux Foundation intro courses are a good base), get light hands-on with kubectl to make the concepts concrete, then drill practice questions until the terminology is automatic. Our KCNA question bank covers every domain with explanations, and the Playbook distills the concepts the exam emphasizes.
The natural next step is the hands-on Certified Kubernetes Administrator (CKA) or Application Developer (CKAD), depending on whether you lean toward operating clusters or building apps on them. Browse the full Kubernetes track to plan your path.
KCSA stands for Kubernetes and Cloud Native Security Associate — the CNCF's foundational, multiple-choice certification for Kubernetes security concepts: the 4Cs of cloud-native security, cluster and workload hardening, common threats, and relevant CNCF security projects. It's the conceptual counterpart to the hands-on CKS. See the KCSA hub for the full scope.
Yes — KCSA is a 60-question multiple-choice exam (not hands-on), and it's a foundational, concept-level test, so it's approachable in a couple of weeks for most people with some Kubernetes background. The main work is learning the security terminology and threat models. Practice questions are the quickest readiness check.
Yes, if you're moving toward Kubernetes security or want to prove security literacy before the hands-on CKS — it's an affordable foundation and a sensible precursor. It's newer and narrower, so it's most valuable as a stepping stone or for security-adjacent roles. See how it compares on our State of Certifications report.
60 multiple-choice questions in 90 minutes, closed-book and remotely proctored, with a passing score around 75%. It costs about $250 USD (including one free retake) and is valid for 2 years. Scheduling details are on our Kubernetes exam info page.
Study the CNCF cloud-native security model (the 4Cs), Kubernetes hardening (RBAC, network policies, pod security), common attack vectors, and the relevant security projects — the Linux Foundation's security intro material is a good base. Then drill practice questions. Our KCSA question bank covers every domain with explanations, and the Playbook distills the security concepts it tests.
The natural progression is the hands-on Certified Kubernetes Security Specialist (CKS) — though note CKS requires an active CKA first, so most people go KCSA → CKA → CKS. Browse the full Kubernetes track to plan your path.
CNPA is the CNCF's foundational certification for platform engineering — building internal developer platforms on Kubernetes and cloud-native tooling. Platform engineering is the practice of creating self-service platforms (golden paths, internal tooling, GitOps, developer portals) that let application teams ship quickly without wrestling with infrastructure. The exam is multiple-choice; see the CNPA hub for the full scope.
It's aimed at platform engineers, DevOps engineers, and SREs building internal developer platforms on cloud-native foundations — and anyone wanting to validate knowledge of this fast-growing discipline. As a newer foundational cert it's most valuable as a way to formalize platform-engineering concepts; pair it with hands-on Kubernetes certs for engineering roles. See how the Kubernetes track compares on our State of Certifications report.
Study platform-engineering concepts — internal developer platforms, golden paths, GitOps and CI/CD, observability, and the CNCF tooling ecosystem — on top of solid Kubernetes fundamentals. It's a 60-question multiple-choice exam, valid 2 years. Our CNPA question bank covers the domains with explanations, and the Playbook distills the platform-engineering concepts it tests.
It's the CNCF's professional-level certification for Kubernetes administrators — installing and configuring clusters, managing workloads, networking, storage, and troubleshooting. Crucially, it's a hands-on, performance-based exam: you solve real tasks in a live terminal, not multiple-choice questions. See the CKA hub for the full scope.
It's genuinely challenging because it's practical and timed — around 2 hours to complete a set of hands-on tasks on real clusters, so you need fluent kubectl and real troubleshooting ability, not memorization. Speed matters as much as knowledge. The best preparation is repeated hands-on practice; our CKA practice questions and Playbook reinforce the command patterns and troubleshooting flow the exam demands.
Both, in a specific way: the entire exam is hands-on in a live terminal, and during it you're allowed to open one browser tab to the official Kubernetes documentation (kubernetes.io) — and nothing else. So it's "open book" only to the official docs; there's no access to Google, notes, or other sites. Knowing your way around the docs quickly is part of the skill.
Yes — CKA is one of the most respected, in-demand certifications in cloud-native, precisely because it proves you can actually operate Kubernetes, not just describe it. Kubernetes administration is a well-paid specialization (pay varies by region and seniority), and CKA frequently appears in job requirements. See how it ranks on our State of Certifications report.
Get deeply hands-on with kubectl on real clusters — deployments, services, networking, storage, RBAC, and especially troubleshooting — and practice under a timer, since pacing is half the battle. Learn to navigate the official docs fast. Our CKA question bank and Playbook target exactly those hands-on skills and the exam's time pressure.
Yes — it's valid for 2 years. You recertify by retaking the current exam before it expires. The exam tracks recent Kubernetes versions, so a retake also keeps your skills current with the latest releases.
Around $445 USD — more than most multiple-choice exams because it's performance-based: it runs live clusters, live proctoring, and includes one free retake. That infrastructure (and the retake safety net) is what you're paying for. Scheduling and system requirements are on our Kubernetes exam info page.
Yes — you can reschedule through the exam provider (PSI), generally up to 24 hours before your appointment, without losing the attempt. Our Kubernetes exam info page covers the scheduling and reschedule process and the workspace requirements for the remote exam.
They run Kubernetes clusters in production — provisioning and upgrading clusters, deploying and scaling workloads, managing networking, storage, and access, monitoring health, and troubleshooting when things break. CKA validates exactly this operational skill set, which is why it's a hands-on rather than a written exam.
It's the CNCF's professional-level certification for developers who build and run applications on Kubernetes — defining, deploying, configuring, and observing workloads (pods, deployments, services, config, probes) rather than administering the cluster itself. Like the CKA, it's a hands-on, performance-based exam in a live terminal. See the CKAD hub for the full scope.
They test different roles on the same platform. CKA is for cluster administrators — installing, upgrading, networking, storage, and troubleshooting the cluster. CKAD is for application developers — packaging, deploying, configuring, and observing apps that run on Kubernetes. Both are hands-on and share a lot of core knowledge, but CKA goes deeper on cluster operations while CKAD goes deeper on the workload/app side.
Most people find CKAD slightly more approachable — it's narrower (app-focused, no cluster install/upgrade or deep node troubleshooting) and the tasks are often faster to complete. That said, it's still a timed, hands-on exam, so it's not "easy," and the two are close in overall difficulty. Your background decides it: developers often prefer CKAD, ops folks CKA.
It's challenging because it's practical and timed — around 2 hours of hands-on tasks where fluent kubectl and speed matter as much as knowledge. If you build on Kubernetes regularly it's very doable; if you've only studied theory, the time pressure is tough. Repeated timed practice is the key; our CKAD practice questions and Playbook reinforce the workflows.
Yes to both, with the same rule as CKA: it's entirely hands-on in a live terminal, and you may open one browser tab to the official Kubernetes documentation (kubernetes.io) during the exam — nothing else. It's not multiple choice, and it's "open book" only to the official docs.
Yes, if you develop applications that run on Kubernetes — it proves practical, job-relevant skill and is well recognized for cloud-native developer roles. It pairs naturally with CKA if you want to cover both the app and cluster sides. See how it ranks on our State of Certifications report.
Practice building and deploying real workloads with kubectl — deployments, services, config maps/secrets, probes, resource limits, and multi-container patterns — under a timer, and get fast at the official docs. It costs around $445 (with one free retake) and is valid 2 years. Our CKAD question bank and Playbook target exactly those hands-on skills.
It's the CNCF's professional-level certification for securing Kubernetes — cluster hardening, supply-chain security, runtime security, network policies, and minimizing attack surface. Like CKA and CKAD, it's a hands-on, performance-based exam in a live terminal, and it's the most advanced of the Kubernetes certifications. See the CKS hub for the full scope.
No, you can't take CKS without CKA. The CKS has a hard prerequisite: you must hold a current, active Certified Kubernetes Administrator (CKA) certification to schedule and sit the CKS exam. This is unusual among certs, so plan to earn (and keep valid) your CKA first.
No — CKS and CKA have separate 2-year validity periods, and passing CKS does not extend or renew your CKA. You need an active CKA to take CKS, but afterward each certification expires on its own timeline, so keep track of both renewal dates.
Generally yes — CKS builds on CKA (which is why CKA is required first) and adds a specialized, deep security layer with tools like runtime detection, admission control, and supply-chain scanning. It assumes you already have the cluster fluency CKA proves, then tests security skills on top, so most people find it the toughest of the three. Heavy hands-on practice is essential; our CKS practice questions and Playbook target the security tasks.
Yes, if you work in Kubernetes security or platform security — it's the recognized specialist credential and cloud-native security is in high demand. Because it requires CKA first, it signals both broad admin skill and deep security ability. See how it ranks on our State of Certifications report.
Yes — it's entirely hands-on in a live terminal, and during the exam you may access the official Kubernetes documentation (kubernetes.io), plus a small set of allowed security-tool docs, in one browser tab. It's not multiple choice, and outside of those official sources it's closed.
First earn and keep an active CKA, then get hands-on with the security stack — RBAC, network policies, pod security standards, runtime tools (like Falco), admission control, and image/supply-chain scanning — and practice under a timer. It costs around $445 (with one free retake) and is valid 2 years. Our CKS question bank and Playbook reinforce those hands-on security skills.
CNPE is the CNCF's professional-level, hands-on certification for platform engineering — building and operating internal developer platforms on Kubernetes and the cloud-native ecosystem. A platform engineer builds the self-service "golden paths," tooling, and automation (GitOps, CI/CD, observability, developer portals) that let application teams ship quickly without managing infrastructure themselves. See the CNPE hub for the full scope.
It's aimed at experienced platform engineers, DevOps engineers, and SREs who design internal developer platforms — and it's worth it if platform engineering is your focus, since it's one of the first hands-on certifications for this fast-growing discipline. Because it's performance-based, it's a strong differentiator. It suits people who already have solid Kubernetes experience rather than beginners. See how the Kubernetes track compares on our State of Certifications report.
Build real internal-platform capabilities on Kubernetes — GitOps pipelines, self-service provisioning, observability, and developer-facing tooling — and get hands-on with the CNCF ecosystem projects, since it's a performance-based exam. It's valid 2 years. Our CNPE question bank and Playbook target the platform-engineering skills and patterns it tests.