Be able to bootstrap a cluster with kubeadm, join nodes, and repair a NotReady control plane by reading kubelet logs and static pod manifests. The single most important thing: after any manifest or config change, verify the component actually restarted and the node returns to Ready.
Start practicing
Cluster Architecture, Installation & Configuration — choose a session length
Free · No account required
Domain overview
This domain covers bootstrapping and maintaining Kubernetes control planes and nodes with kubeadm, plus static pod manifests, kubelet configuration, certificates, and cluster upgrades. CKA tasks here are hands-on: you run kubeadm commands, inspect kubelet and container runtime state, edit manifests under /etc/kubernetes/manifests, and repair broken control plane or node components.
Exam objectives
Running kubeadm init, kubeadm join, and kubeadm token create --print-join-command for cluster membership
Inspecting kubelet health with systemctl status kubelet and journalctl -u kubelet for startup failures
Managing static pods in /etc/kubernetes/manifests for kube-apiserver, kube-controller-manager, kube-scheduler, and etcd
Performing kubeadm upgrade plan and kubeadm upgrade apply, then draining and upgrading nodes
Re-running kubeadm init on a dirty host without kubeadm reset, leaving stale certificates, etcd data, or CNI config that breaks the new control plane.
Editing static pod manifests directly but forgetting the kubelet restarts them automatically, so changes must be valid YAML or the component crash-loops.
Confusing kubelet service failures with container runtime failures; checking only kubectl output instead of journalctl and crictl to find the real cause.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A DevOps engineer notices that the kubelet on a node is unable to register with the Kubernetes API server. The kubelet logs show 'Failed to get bootstrap CA certificate' and the node is not yet part of the cluster. What is the most likely cause?
2A Kubernetes cluster has been running for months. Recently, some pods are reporting 'FailedScheduling' due to insufficient memory. The administrator wants to add a new node with 32GB RAM. However, after joining the node, the new node shows 'NotReady' and the kubelet logs indicate 'Failed to update node status: context deadline exceeded'. What is the most likely cause?
3An administrator is tasked with setting up a new Kubernetes cluster using kubeadm. They have two nodes: one control plane and one worker. After initializing the control plane with 'kubeadm init', the worker node fails to join with the error 'error execution phase preflight: [preflight] Some fatal errors occurred: [ERROR CRI]: container runtime is not running'. What should the administrator check first?
4A team is configuring etcd for a multi-node Kubernetes cluster. They want to ensure that etcd data is encrypted at rest. Which approach should they use?
5During a 'kubeadm init', the administrator sees the message 'Your Kubernetes control-plane has been initialized successfully!' but the 'kubectl get nodes' shows the control plane node as 'NotReady'. What is the most likely missing step?
6A user tries to create a pod with the YAML file that requests 2 CPUs as a limit. The cluster has a ResourceQuota named 'compute-quota' with limits.cpu: 2. The user sees the above error. What is the likely issue?
7An administrator runs 'kubeadm init' on a machine that previously had a Kubernetes cluster. The command fails with the above errors. What is the best course of action?
8You are a cluster administrator managing a multi-node Kubernetes cluster version 1.22. The cluster runs critical applications in the 'production' namespace. You have been asked to upgrade the control plane node to version 1.23 while minimizing downtime. The cluster uses a single control plane node (not HA). You have already backed up etcd and verified the backup is valid. You have also reviewed the upgrade notes and there are no breaking changes that affect your workloads. You have drained the control plane node and ensured all pods are evicted. The node is now in 'Ready,SchedulingDisabled' state. You then run 'kubeadm upgrade plan' and see that upgrade to v1.23.0 is available. Next, you run 'kubeadm upgrade apply v1.23.0'. The command completes successfully. However, when you try to uncordon the node with 'kubectl uncordon <node>', you get an error: 'error: unable to update node: the object has been modified; please apply your changes to the latest version and try again'. What is the most likely cause and the correct next step?
9A Kubernetes cluster has three control plane nodes and five worker nodes. The kube-apiserver is failing to start on one control plane node with the error 'etcdserver: request timed out'. The etcd cluster is healthy with three members. Which of the following is the most likely cause?
10An administrator needs to initialize a new Kubernetes control plane node using kubeadm. Which of the following is the correct command to initialize the control plane with a specific pod network CIDR of 10.244.0.0/16?
11A system administrator needs to install a Kubernetes cluster using kubeadm. The control plane node must be initialized with a specific Pod network CIDR of 10.244.0.0/16 for Flannel. Which command should be used?
12A Kubernetes cluster is running with a single control plane node. The administrator wants to add a second control plane node for high availability. What is the first step after the new node has been provisioned with the required software?
13A cluster administrator notices that nodes are not joining the cluster after a kubeadm init. The kubelet logs show: 'failed to run Kubelet: could not init service: open /var/lib/kubelet/config.yaml: permission denied'. What is the most likely cause?
14A DevOps engineer is designing a Kubernetes cluster for a production environment. Which of the following is a best practice for etcd deployment?
15Refer to the exhibit. A Kubernetes cluster was initialized using kubeadm with the command shown. After initialization, the cluster nodes are in NotReady state. Which is the most likely missing step?
16Refer to the exhibit. The master node shows NotReady status. The kubelet is reporting 'container runtime is down'. Which command should be used to investigate and fix this issue?
17Refer to the exhibit. A new worker node (node2) has been added to the cluster. It shows NotReady status, and a CertificateSigningRequest (CSR) is pending. What step must the cluster administrator take to make node2 ready?
18Refer to the exhibit. An administrator creates a token with TTL 0. What is the effect on the token?
19An administrator is preparing a bare-metal node to join an existing kubeadm cluster. The node has containerd installed and running, swap disabled, and the required kernel modules loaded. Before running kubeadm join, which command should the administrator run to ensure the kubelet registers with the API server using the correct node name?
Be able to bootstrap a cluster with kubeadm, join nodes, and repair a NotReady control plane by reading kubelet logs and static pod manifests. The single most important thing: after any manifest or config change, verify the component actually restarted and the node returns to Ready.
The Courseiva CKA question bank contains 19 questions in the Cluster Architecture, Installation & Configuration domain, covering the 12% of the exam attributed to this domain in the official CNCF blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Cluster Architecture, Installation & Configuration domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included