CKA Practice Question: Cluster Architecture, Installation and Configuration
To check the expiration date of all certificates managed by kubeadm, which command should you run?
⚠ Common exam trap
Many exam-takers confuse `kubeadm certs check-expiration` with `kubeadm alpha certs check-expiration` (option D) from older kubeadm versions, or mistakenly think `kubectl` can inspect filesystem certificates (option A), when in fact only the `kubeadm` CLI with the correct subcommand can perform this check.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubeadm certs check-expiration
`kubeadm certs check-expiration` is the dedicated kubeadm command to display expiration dates for all certificates managed by kubeadm in the cluster. This command reads the certificate files from the default kubeadm certificate directory (typically `/etc/kubernetes/pki`) and parses their `NotAfter` field to show remaining validity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl get certificates
Why it's wrong here
There is no built-in Kubernetes API resource named `certificates`. Kubernetes handles certificate signing requests via `CertificateSigningRequest` (CSR) objects, retrieved with `kubectl get csr`, but those are approval requests, not the actual certificates managed by kubeadm. Therefore this command would fail with an "the server doesn't have a resource type" error and provides no expiration information.
- ✓
kubeadm certs check-expiration
Why this is correct
`kubeadm certs check-expiration` is the canonical command for inspecting the lifecycle of all certificates generated by kubeadm. It reads the PKI files under `/etc/kubernetes/pki` and the embedded etcd certificates, and outputs each certificate's name, remaining validity, and expiration date. This stable subcommand is the direct way to verify expiration before planning renewals.
- ✗
kubeadm certs renew
Why it's wrong here
`kubeadm certs renew` is for renewing the kubeadm-managed certificates, either all of them with `kubeadm certs renew all` or individually, such as `kubeadm certs renew apiserver`. It does not display expiration dates; running it just regenerates certificates and writes new files. As a renewal operation, it is intended only after checking expiration, not as a diagnostic.
- ✗
kubeadm alpha certs check-expiration
Why it's wrong here
The `alpha` subcommand was used in earlier Kubernetes versions when the certificates management commands were still experimental. However, `check-expiration` is now a stable, GA subcommand of `kubeadm certs`, so invoking it under `kubeadm alpha certs` calls an outdated and non-existent command path. The correct usage omits `alpha` entirely: `kubeadm certs check-expiration`.
Go deeper
Related to this question
Learn chapter
Kubernetes Architecture Overview
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.