CKA Practice Question: Cluster Architecture, Installation and Configuration
Which command is used to check the expiration of certificates managed by kubeadm?
⚠ Common exam trap
Watch out — candidates often confuse `kubeadm certs check-expiration` with `kubeadm certs renew`, thinking the latter also shows expiration status, but `renew` only performs the renewal action without displaying current expiration data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubeadm certs check-expiration
The correct command to check the expiration of certificates managed by kubeadm is `kubeadm certs check-expiration`. This command reads the certificate files located in `/etc/kubernetes/pki/` and displays their remaining validity period, allowing administrators to proactively renew certificates before they expire.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubeadm certs status
Why it's wrong here
The kubeadm certs command group has no status subcommand. Running `kubeadm certs status` returns an error because the only inspection command available under kubeadm certs is `check-expiration`. Status is not a valid verb in kubeadm's certificate management surface, so this command cannot report certificate expiry.
- ✓
kubeadm certs check-expiration
Why this is correct
`kubeadm certs check-expiration` is the dedicated subcommand that inspects certificates under /etc/kubernetes/pki and prints a table with each certificate's expiration date and time remaining before it expires. It also flags certificates that are externally managed and warns when renewal should happen. This read-only command is the standard way to verify certificate validity on a kubeadm-created cluster.
- ✗
kubeadm certs list
Why it's wrong here
`kubeadm certs list` does not exist; kubeadm differentiates itself from kubectl by avoiding generic list verbs and does not provide an inventory-style listing of certificate files. The command would be rejected as unknown, and you must use `check-expiration` for validity details. There is no list subcommand in the kubeadm certs command group.
- ✗
kubeadm certs renew
Why it's wrong here
`kubeadm certs renew` triggers the renewal process, writing new signed certificates to disk, rather than reporting on their current expiry. If used to check expiration, it would modify cluster PKI and can cause control plane components to reload if you renew every certificate. Renewal is an operational action, not a diagnostic query, so it cannot answer an expiration-checking question.
Go deeper
Related to this question
Learn chapter
Kubernetes Architecture Overview
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.