PUT YOUR PRACTICE TO THE TEST
See what you can do on your own.
Timed Kubernetes assessments, a score by objective, and a clearer idea of what to practice next. Hints and solutions stay locked while the scored clock runs.
Working toward an exam date? Explore the $59 Exam Pass: 30 days of access, with an extension if you qualify.Exam Pass →Certified Kubernetes Application Developer
4 exams
A timed, weighted mock exam: six questions spanning configuration, deployments and probes, services, jobs, network policy, and workload hardening — scored as one, calibrated a notch above the real CKAD.
A second timed, weighted mock exam: six fresh questions spanning multi-container pods, init containers, persistent storage, secret wiring, ingress, and right-sizing — a different draw from Simulator 1, scored as one.
A timed troubleshooting mock: six workloads are up but subtly broken — a Service with no endpoints, a wrong target port, a noisy config, an unapproved image, an over-open network policy, and an under-powered role. Diagnose and fix each against the clock.
The hardest tier: three tasks, each fusing what the exam asks one question at a time — config + storage, then a single workload that must satisfy a dozen exact requirements at once, then exposure, isolation and availability. Tighter and stricter than the real exam or killer.sh. Pass mark 75%.
Certified Kubernetes Administrator
3 exams
A timed, weighted administration mock: six questions spanning cluster RBAC, pod priority, autoscaling, storage classes, namespace quotas, and rolling deployments — the workload-and-scheduling half of CKA that runs on one cluster, scored as one.
The services-and-networking and troubleshooting half of CKA, scored as one timed paper: expose a Deployment, restrict it with a NetworkPolicy, route with an Ingress, then diagnose and repair a Service with no endpoints, a Pod that won't schedule, a crash-looping container, and a denied ServiceAccount.
The hardest administration tier: cluster-wide access and priority, one workload operated to spec (resourced, prioritised, autoscaled, probed, with storage), and namespace governance plus exposure — three fused tasks, stricter than the exam or killer.sh. Pass mark 75%.
Certified Kubernetes Security Specialist
2 exams
A timed, weighted security mock: six questions spanning least-privilege RBAC, workload hardening, default-deny networking, Pod Security enforcement, TLS material, and hardened secret handling — scored as one, calibrated a notch above the real CKS.
The hardest security tier: lock a namespace end to end in three fused tasks — enforce/audit/warn Pod Security plus least-privilege identity, a workload hardened on every axis and consuming a secret safely, then full ingress AND egress isolation. Stricter than the exam or killer.sh. Pass mark 75%.
Kyverno Certified Associate
2 exams
A timed, weighted Kyverno mock: five questions across validate, mutate, generate, image rules, and resource enforcement — each scoped to its own namespace, each proven live. Scored as one, calibrated a notch above the exam.
The hardest Kyverno tier: a multi-rule guardrail policy that enforces four constraints at once, a mutate policy that injects several defaults, and a generate policy that seeds two resources per namespace — stricter than the exam or killer.sh. Pass mark 75%.
Sign in to track your readiness and attempts.