Courseiva

CKA Practice Question: Cluster Architecture, Installation and Configuration

To check the expiration date of all certificates managed by kubeadm, which command should you run?

⚠ Common exam trap

Many exam-takers confuse `kubeadm certs check-expiration` with `kubeadm alpha certs check-expiration` (option D) from older kubeadm versions, or mistakenly think `kubectl` can inspect filesystem certificates (option A), when in fact only the `kubeadm` CLI with the correct subcommand can perform this check.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubeadm certs check-expiration

`kubeadm certs check-expiration` is the dedicated kubeadm command to display expiration dates for all certificates managed by kubeadm in the cluster. This command reads the certificate files from the default kubeadm certificate directory (typically `/etc/kubernetes/pki`) and parses their `NotAfter` field to show remaining validity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl get certificates

    Why it's wrong here

    There is no built-in Kubernetes API resource named `certificates`. Kubernetes handles certificate signing requests via `CertificateSigningRequest` (CSR) objects, retrieved with `kubectl get csr`, but those are approval requests, not the actual certificates managed by kubeadm. Therefore this command would fail with an "the server doesn't have a resource type" error and provides no expiration information.

  • ✓

    kubeadm certs check-expiration

    Why this is correct

    `kubeadm certs check-expiration` is the canonical command for inspecting the lifecycle of all certificates generated by kubeadm. It reads the PKI files under `/etc/kubernetes/pki` and the embedded etcd certificates, and outputs each certificate's name, remaining validity, and expiration date. This stable subcommand is the direct way to verify expiration before planning renewals.

  • ✗

    kubeadm certs renew

    Why it's wrong here

    `kubeadm certs renew` is for renewing the kubeadm-managed certificates, either all of them with `kubeadm certs renew all` or individually, such as `kubeadm certs renew apiserver`. It does not display expiration dates; running it just regenerates certificates and writes new files. As a renewal operation, it is intended only after checking expiration, not as a diagnostic.

  • ✗

    kubeadm alpha certs check-expiration

    Why it's wrong here

    The `alpha` subcommand was used in earlier Kubernetes versions when the certificates management commands were still experimental. However, `check-expiration` is now a stable, GA subcommand of `kubeadm certs`, so invoking it under `kubeadm alpha certs` calls an outdated and non-existent command path. The correct usage omits `alpha` entirely: `kubeadm certs check-expiration`.

About these practice questions

This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.