Courseiva

CKA Practice Question: Cluster Architecture, Installation and Configuration

You need to check the expiration date of certificates used by the kube-apiserver. Which command should you use?

⚠ Common exam trap

It's easy for candidates to confuse `kubeadm certs check-expiration` with `kubeadm certs renew` (option A) or think that `openssl` (option C) is the only way to inspect certificates, but the CKA exam expects you to know the kubeadm-specific command for checking expiration as part of cluster maintenance tasks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubeadm certs check-expiration

`kubeadm certs check-expiration` is the dedicated kubeadm command to display the expiration dates of all certificates managed by kubeadm in the cluster, including the kube-apiserver certificate. This command reads the certificate files from `/etc/kubernetes/pki/` and outputs the remaining validity period for each, making it the most direct and accurate method for checking certificate expiration in a kubeadm-deployed cluster.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubeadm certs renew

    Why it's wrong here

    While this command is part of the kubeadm certificate management suite, its purpose is to actively generate and replace existing control plane certificates with new ones. Running this command will modify the cluster's state by extending the validity of the certificates for another year, rather than simply displaying their current expiration status.

  • ✗

    kubectl get secrets -n kube-system

    Why it's wrong here

    This command queries Kubernetes Secret resources within the kube-system namespace, which typically store service account tokens or TLS credentials for ingress/addons. However, the core control plane certificates managed by kubeadm are stored as physical files on the host filesystem under /etc/kubernetes/pki, not as Kubernetes Secrets, and this command cannot parse or display certificate expiration metadata.

  • ✗

    openssl x509 -in /etc/kubernetes/pki/apiserver.crt -text -noout

    Why it's wrong here

    Although this command successfully extracts and displays the validity dates of a single certificate file (the API server certificate), it is not the most efficient or standard way to check the entire control plane. It requires running the command individually for every single certificate file in the PKI directory, whereas the question seeks a unified command to check all cluster certificates at once.

  • ✓

    kubeadm certs check-expiration

    Why this is correct

    This is the correct and standard administrative command used to inspect the expiration status of all Kubernetes control plane certificates managed by kubeadm. It scans the /etc/kubernetes/pki directory and the embedded certificates within the kubeconfig files, outputting a clean, tabular summary of the residual lifetime, expiration date, and authority for each certificate.

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.