Courseiva

CKA Practice Question: Cluster Architecture, Installation and Configuration

Which command is used to check the expiration of certificates managed by kubeadm?

⚠ Common exam trap

Watch out — candidates often confuse `kubeadm certs check-expiration` with `kubeadm certs renew`, thinking the latter also shows expiration status, but `renew` only performs the renewal action without displaying current expiration data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubeadm certs check-expiration

The correct command to check the expiration of certificates managed by kubeadm is `kubeadm certs check-expiration`. This command reads the certificate files located in `/etc/kubernetes/pki/` and displays their remaining validity period, allowing administrators to proactively renew certificates before they expire.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubeadm certs status

    Why it's wrong here

    The kubeadm certs command group has no status subcommand. Running `kubeadm certs status` returns an error because the only inspection command available under kubeadm certs is `check-expiration`. Status is not a valid verb in kubeadm's certificate management surface, so this command cannot report certificate expiry.

  • ✓

    kubeadm certs check-expiration

    Why this is correct

    `kubeadm certs check-expiration` is the dedicated subcommand that inspects certificates under /etc/kubernetes/pki and prints a table with each certificate's expiration date and time remaining before it expires. It also flags certificates that are externally managed and warns when renewal should happen. This read-only command is the standard way to verify certificate validity on a kubeadm-created cluster.

  • ✗

    kubeadm certs list

    Why it's wrong here

    `kubeadm certs list` does not exist; kubeadm differentiates itself from kubectl by avoiding generic list verbs and does not provide an inventory-style listing of certificate files. The command would be rejected as unknown, and you must use `check-expiration` for validity details. There is no list subcommand in the kubeadm certs command group.

  • ✗

    kubeadm certs renew

    Why it's wrong here

    `kubeadm certs renew` triggers the renewal process, writing new signed certificates to disk, rather than reporting on their current expiry. If used to check expiration, it would modify cluster PKI and can cause control plane components to reload if you renew every certificate. Renewal is an operational action, not a diagnostic query, so it cannot answer an expiration-checking question.

About these practice questions

This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.