A free, open study guide for the Kubernetes and Cloud Native Associate (KCNA) (KCNA) exam: revision notes for every domain, side-by-side comparisons of commonly confused services, a glossary, 20 worked sample questions, and the official syllabus as a checklist with a full free lesson for every topic.
Maintained by SaveMyCert, where you can read every lesson free, practice with explained questions and take timed mock exams.
- Exam at a glance
- Exam domains
- What is in this repo
- Syllabus checklist
- How to study for KCNA
- Sample questions
- Free resources
| Exam code | KCNA |
| Level | Foundational |
| Questions | ~60 |
| Time limit | 90 min |
| Passing score | 75% |
| Format | Multiple choice |
| Exam fee | $250 |
| Valid for | 2 years |
Exam details change. Always confirm them in the official KCNA certification page and curriculum from The Linux Foundation.
| # | Domain | Weight | Topics |
|---|---|---|---|
| 1 | Kubernetes Fundamentals | 44% | 4 |
| 2 | Container Orchestration | 28% | 4 |
| 3 | Cloud Native Application Delivery | 16% | 2 |
| 4 | Cloud Native Architecture | 12% | 3 |
That is 4 domains and 13 topics. Spend your time in proportion to the weights: the heaviest domain decides more of your score than the lightest.
| File | What it gives you |
|---|---|
| Domain 1 notes | Kubernetes Fundamentals: condensed revision notes per topic |
| Domain 2 notes | Container Orchestration: condensed revision notes per topic |
| Domain 3 notes | Cloud Native Application Delivery: condensed revision notes per topic |
| Domain 4 notes | Cloud Native Architecture: condensed revision notes per topic |
| Commonly confused services | Side-by-side tables of the services questions set against each other |
| Glossary | Every in-scope term and service in one sentence |
| Sample questions | 20 worked questions with answers and reasoning |
| Exam-day guide | Booking, testing options, scoring, results and retakes |
Tick each topic off once you can explain it without notes. The "Must know" facts are the ones questions turn on. Each lesson link goes to the complete, free lesson.
Weight: 44%. The Kubernetes object model, cluster administration, scheduling, and containerization. Official weighting 44%.
π Revision notes: Domain 1: Kubernetes Fundamentals
- Kubernetes Core Concepts
The Kubernetes architecture and object model: control plane vs worker nodes, the API server and etcd, controllers and desired-state reconciliation, and the core resources (Pods, ReplicaSets, Deployments, Services, namespaces) with declarative configuration.- π Lesson: Kubernetes Core Concepts: Architecture, Pods, Deployments, and Services
- Must know: A Pod is the smallest deployable unit; its containers share one network namespace (one IP) and can share volumes.
- Must know: The kube-apiserver is the front door: kubectl, the kubelet, and all controllers talk to the cluster only through it.
- Administration
Managing a Kubernetes cluster: kubectl and the API, the cluster components (kube-apiserver, kube-scheduler, kube-controller-manager, kubelet, kube-proxy), role-based access control (RBAC) basics, namespaces, and resource quotas.- π Lesson: Kubernetes Administration: kubectl, RBAC, Namespaces, and Resource Quotas
- Must know: Every kubectl command is an HTTPS request to the kube-apiserver; kubectl never talks to nodes or etcd directly.
- Must know: kubectl apply is declarative and idempotent; create, run, scale, and expose are imperative one-off commands with no file as source of truth.
- Scheduling
How the scheduler places Pods onto nodes: resource requests and limits, node selectors, affinity and anti-affinity, taints and tolerations, and scheduling constraints.- π Lesson: Kubernetes Scheduling: Requests, Node Affinity, Taints and Tolerations
- Must know: The kube-scheduler works in two phases: filter out infeasible nodes, then score the feasible ones and bind the Pod to the winner.
- Must know: Requests drive scheduling and reserve capacity; limits are enforced at runtime and play no part in placement.
- Containerization
Container fundamentals underpinning Kubernetes: images and registries, container runtimes and the Container Runtime Interface (CRI), Open Container Initiative (OCI) standards, and building and running containers.- π Lesson: Containerization: Images, Container Runtimes, CRI and the OCI Explained
- Must know: A container is an isolated process on a shared host kernel: namespaces control what it sees, cgroups control what it uses.
- Must know: Containers virtualize the operating system; VMs virtualize the hardware and each carry their own guest kernel.
Weight: 28%. Networking, security, troubleshooting, and storage for orchestrated workloads. Official weighting 28%.
π Revision notes: Domain 2: Container Orchestration
- Networking
The Kubernetes networking model: Pod-to-Pod networking, Services and kube-proxy, cluster DNS, the Container Network Interface (CNI), Ingress, and network policies.- π Lesson: Kubernetes Networking: Services, kube-proxy, CNI, DNS, and Ingress
- Must know: Every Pod gets its own IP address, and Pods communicate across nodes without NAT; that flat model is implemented by the CNI plugin, not by Kubernetes itself.
- Must know: A Service provides a stable virtual IP and DNS name in front of ephemeral Pods, selected by labels and tracked through EndpointSlices.
- Security
Cloud-native and Kubernetes security basics: the 4Cs of cloud-native security, RBAC and service accounts, Secrets, and the container, network, and policy security surface.- π Lesson: Kubernetes Security: The 4Cs, RBAC, Secrets, and Pod Security Admission
- Must know: The 4Cs are Cloud, Cluster, Container, Code: nested layers of defense in depth, where each inner layer depends on the security of the layers outside it.
- Must know: RBAC is additive and allow-only: Roles and ClusterRoles grant verbs on resources, bindings attach them to subjects, and anything not granted is denied.
- Troubleshooting
Diagnosing workloads and clusters: reading Pod status and events, kubectl logs / describe / exec, and identifying common failure modes across Pods, Services, and nodes.- π Lesson: Troubleshooting Kubernetes: Pod Status, Events, Logs, and Probes
- Must know: The five Pod phases are Pending, Running, Succeeded, Failed, and Unknown; the STATUS column of kubectl get pods shows more specific reasons like CrashLoopBackOff.
- Must know: ImagePullBackOff means the image cannot be pulled (bad name, tag, or credentials); CrashLoopBackOff means the image ran but the container keeps exiting.
- Storage
Kubernetes storage: Volumes, PersistentVolumes and PersistentVolumeClaims, StorageClasses and dynamic provisioning, and the Container Storage Interface (CSI).- π Lesson: Kubernetes Storage: Volumes, PersistentVolumes, PVCs, and CSI
- Must know: A Volume is declared in the Pod spec and (for ephemeral types like emptyDir) lives and dies with the Pod; emptyDir survives container restarts but not Pod deletion.
- Must know: PersistentVolumes are the cluster-scoped supply of storage; PersistentVolumeClaims are namespaced requests that bind to them one-to-one, and Pods reference the claim, never the PV.
Weight: 16%. Delivering and debugging applications on cloud-native platforms. Official weighting 16%.
π Revision notes: Domain 3: Cloud Native Application Delivery
- Application Delivery
Delivering applications on Kubernetes: deployment strategies and rollouts, GitOps and CI/CD fundamentals, package management with Helm, and the application definition and image-build landscape.- π Lesson: Cloud Native Application Delivery: GitOps, Helm, and Deployment Strategies
- Must know: RollingUpdate is the default Deployment strategy; Recreate stops all old Pods first and causes downtime
- Must know: Blue-green and canary are patterns, not strategy field values; canary traffic splitting typically needs a service mesh or Argo Rollouts
- Debugging
Debugging application delivery: inspecting Deployments and rollouts, diagnosing failed releases, and using observability signals during delivery.- π Lesson: Debugging Application Delivery: Stuck Rollouts, Failed Releases, and Rollbacks
- Must know: A rolling update only progresses as new Pods pass readiness probes; a bad release stalls while the old ReplicaSet keeps serving
- Must know: kubectl rollout status hangs on a stuck rollout; kubectl get replicasets shows the telltale two-ReplicaSet picture
Weight: 12%. Observability, cloud-native principles and the CNCF ecosystem, and community collaboration. Official weighting 12%.
π Revision notes: Domain 4: Cloud Native Architecture
- Observability
Observability pillars β metrics, logs, and traces; Prometheus and the observability tooling landscape; and cost and performance monitoring.- π Lesson: Observability in Cloud Native: Metrics, Logs, and Traces
- Must know: Metrics measure trends over time, logs record discrete events, traces follow one request across services.
- Must know: Prometheus pulls metrics by scraping HTTP endpoints and stores them as labeled time series queried with PromQL.
- Cloud Native Ecosystem and Principles
Cloud-native principles (autoscaling, serverless, microservices, immutability, declarative APIs) and the CNCF project and ecosystem landscape.- π Lesson: Cloud Native Principles and the CNCF Ecosystem
- Must know: The CNCF definition names five techniques: containers, service meshes, microservices, immutable infrastructure, and declarative APIs.
- Must know: Cloud native systems aim to be loosely coupled, resilient, manageable, and observable, with change driven by automation.
- Cloud Native Community and Collaboration
How the cloud-native community works: CNCF project maturity levels (Sandbox, Incubating, Graduated), governance, open-source collaboration, and the roles and personas in the ecosystem.- π Lesson: CNCF Community, Project Maturity Levels, and Open Source Governance
- Must know: The CNCF is a project of the Linux Foundation and a vendor-neutral home for cloud native open source; Kubernetes was its first hosted project.
- Must know: CNCF projects have exactly three maturity levels, in order: Sandbox, Incubating, Graduated.
- Read the lesson for each topic in the checklist above, starting with the heaviest domain. Every lesson is free on the KCNA revision notes.
- Practice straight after reading. Answer KCNA practice questions on the topic you just read. Each option comes with an explanation of why it is right or wrong.
- Review what you got wrong, re-read that lesson section, and tick the topic off only when you get its questions right.
- Take a full-length KCNA mock exam under the real time limit. Aim to pass mocks comfortably before you book.
- On the last day, skim the KCNA cheat sheet instead of starting anything new.
sample-questions.md has 20 worked KCNA questions with the answer, why each option is right or wrong, and the reasoning steps.
- KCNA certification page and curriculum: the official source (The Linux Foundation)
- KCNA certification overview
- KCNA revision notes: every lesson, free to read
- KCNA practice questions: with an explanation on every option
- KCNA mock exams: full-length and timed
- KCNA cheat sheet: the key facts on one page
- All certification study guides
Spotted an error or an out-of-date fact? Open an issue with the topic and a link to the official source. See CONTRIBUTING.md.
This guide is licensed under CC BY 4.0. You can reuse and adapt it, including commercially, as long as you credit SaveMyCert with a link to https://www.savemycert.com/.
This is an independent study resource. It is not affiliated with or endorsed by The Linux Foundation. Kubernetes and Cloud Native Associate (KCNA) and KCNA are trademarks of their respective owner. Exam domains and weights are taken from the official exam guide linked above.