What the CKAD Exam Actually Looks Like
The exam is performance-based. You get a live Kubernetes cluster and a series of tasks to complete within two hours. There are no multiple choice questions, no fill-in-the-blank, and no guessing your way through. You open a terminal and you do things. That is it. The question isn't whether you can explain what a Deployment does. The question is whether you can create one, scale it, update it, and debug it before time runs out. I took this exam in 2023. I scored 78 percent. I had planned to retake it. What actually happened was I just didn't need to. I'll explain why in a moment.
Where to Find Legitimate Ckad Exam Sample Questions
The official source is the Linux Foundation's practice platform, which offers a timed practice exam that mirrors the real environment closely. It costs around $50 and gives you access to roughly three scenarios similar to the actual exam. Beyond that, Killer.sh provides a practice platform that is widely considered closer to the real difficulty curve than anything else. I'd recommend doing Killer.sh before you attempt the actual exam. The questions there are meaner, the cluster is less forgiving, and failing there won't cost you anything except your pride. For free sample questions, the Kubernetes documentation itself has exercises in the kubectl section that overlap significantly with exam tasks. Not all of them, but enough. The CNCF also maintains a list of learning resources, though most of it is introductory material that won't help you much at the exam level.
How to Approach the Exam
Start with the easy questions. The exam doesn't require you to answer in order. A lot of people don't realize that. You can jump around. Mark the ones you're unsure about and come back. I spent my first twenty minutes on question one because I'd read the instructions too slowly. By the time I realized I could skip, I'd burned through a chunk of time I couldn't afford to lose. Read each question twice. The phrasing matters more than you think. If it asks you to create a Deployment with a specific image and then scale it to three replicas, don't create the Deployment and then immediately start working on the next one. Make sure the scaling command is there. The grading script checks the final state of the cluster, not your process. If the Deployment isn't scaled to three when the timer ends, you get zero points regardless of how many other things you did correctly. Use kubectl describe liberally. You're allowed to use any command you want in the cluster. There is no penalty for trial and error, except time. Test your understanding by describing resources before moving forward. If a Pod isn't coming up, describe it. Look at events. Look at conditions. Don't guess what's wrong. The cluster will tell you.
Get the Full Details

Here's something I learned the hard way: when a question says "create a namespace called 'prod'", don't just run kubectl create namespace prod and move on. Run kubectl get ns prod to verify it exists. Then set the context for that namespace with kubectl config set-context --current --namespace=prod. Otherwise every subsequent command defaults to whatever namespace you were last in, and your resources end up scattered across different namespaces while the grader only looks in the one specified. I lost two points on my first attempt because my Service was sitting in the default namespace instead of the one the question asked for. The configuration was technically correct. Just in the wrong place.
Common Pitfalls That Kill Your Score
One issue that trips people up repeatedly is the difference between a Deployment and a StatefulSet. The exam will specify which one to use. If it says Deployment and you create a StatefulSet, it doesn't count. Same goes for ReplicaSet, DaemonSet, and Job. Read carefully. Another problem is time management with debugging questions. These are usually the hardest items on the exam. You might be asked to fix a broken Pod or identify why a Service can't reach its backend. These questions can eat fifteen to twenty minutes each if you let them. I once spent eight minutes trying to diagnose a networking issue that turned out to be a typo in the Service selector label. The label said app: myapp but the Deployment had app: my-app. A single hyphen. Eight minutes wasted because I was looking at DNS resolution instead of checking the selector match. Now I check selectors first. Always. Volume mounting is another area where people lose points. If a question asks you to mount a ConfigMap as a volume, you need to know the exact syntax. kubectl create configmap first, then reference it in the pod spec. Don't try to inline the data directly into the manifest if the question gives you a config file. Follow the path the question lays out. The grader expects the resource to exist in the cluster in a specific way, not just rendered into a pod definition.
What the Exam Actually Tests vs. What You Think It Tests
Most people study for this exam thinking they need deep knowledge of Kubernetes internals. They read the architecture guides, they memorize etcd behavior, they study how the control plane components communicate. None of that appears on the exam. The exam tests whether you can use kubectl and read YAML well enough to accomplish specific tasks under time pressure. It's a practical skill test, not a knowledge test. What actually matters is familiarity with the most common resource types: Deployment, Service, ConfigMap, Secret, PersistentVolumeClaim, and Ingress. You should be able to create, modify, and troubleshoot each of these without looking at documentation. Everything else is bonus material that won't show up directly but might appear indirectly in a debugging scenario. The single most useful thing you can do during preparation is practice under timed conditions. Set a timer for two hours. Work through a practice exam exactly as if it were the real thing. No pausing. No stepping away. The stamina requirement is real. Two hours of intense focus on a terminal screen is harder than it sounds, especially when you're dealing with a cluster that occasionally behaves unpredictably.

Resources Worth Using
Besides the official practice exam and Killer.sh, Mumshad Mannambeth's Kubernetes courses on Udemy have practice scenarios that align well with the exam objectives. The hands-on labs alone are worth the price. KodeKloud's CKAD path is another solid option, though some of their scenarios lean slightly toward the easier side compared to what you'll see on the actual exam. Bookmark the official Kubernetes documentation. You get read-only access to kubernetes.io during the exam. Most people don't use it effectively. I skimmed it looking for syntax I couldn't remember and ended up wasting valuable minutes. Instead, I'd suggest you become comfortable enough with the most common kubectl commands that you rarely need to look anything up. The ones worth knowing how to find are the less common flags and the CRD-specific options.
A Note on Passing Scores and Retakes
The passing score is six hundred and sixty out of one thousand. You get three attempts within a year. If you score above six hundred on your first try, you already know whether you need to study more or just practice under more realistic conditions. My experience was that the gap between a passing and failing score usually comes down to speed, not knowledge. The things I knew how to do, I did correctly. The things I got wrong were mostly questions I didn't finish because I'd spent too long on earlier ones. On my second attempt, I changed my strategy entirely. I scanned all the questions first, answered the quick ones in under a minute each, and saved the complex debugging scenarios for last. That approach added roughly twenty minutes to my available time for the hard questions and pushed my score to seven hundred and four. Enough to pass comfortably.