Courseiva

CKA Practice Question: Cluster Architecture, Installation and Configuration

You initialize a cluster with 'kubeadm init' and want to join a worker node. What is the correct command to generate the join command?

⚠ Common exam trap

Candidates often assume `kubeadm token list` (Option D) is sufficient to get the join command, but it only shows existing tokens without the required CA cert hash, leading to an incomplete or insecure join attempt.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubeadm token create --print-join-command

`kubeadm token create --print-join-command` generates a new bootstrap token and immediately outputs the full `kubeadm join` command, including the token, control-plane endpoint, and discovery token CA cert hash. This is the recommended way to obtain a ready-to-use join command after initializing the cluster with `kubeadm init`.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    kubeadm token create --print-join-command

    Why this is correct

    This command is the standard way to generate a new bootstrap token and immediately print the complete `kubeadm join` command, including the API server endpoint, the token, and the `--discovery-token-ca-cert-hash`. It simplifies node provisioning by outputting a ready-to-run command for worker nodes.

  • ✗

    kubeadm join --token <token> <control-plane>:6443

    Why it's wrong here

    While this represents the actual command executed on a worker node to join the cluster, it cannot be used on the control plane to generate or retrieve the necessary token and discovery hashes. You must first generate these credentials before you can construct and run this command.

  • ✗

    kubeadm init phase upload-config kubelet

    Why it's wrong here

    This command is a specialized phase of the initialization process that uploads the `KubeletConfiguration` to a ConfigMap in the cluster. It does not generate bootstrap tokens or output the join command required for new nodes to authenticate and register.

  • ✗

    kubeadm token list

    Why it's wrong here

    This command displays active bootstrap tokens along with their creation times and expirations, but it does not assemble or print the complete join command. It lacks the critical CA certificate discovery hash required for secure node joining.

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.