Courseiva

CKA Practice Question: Cluster Architecture, Installation and Configuration

You need to renew all certificates on a kubeadm-managed cluster. Which command accomplishes this?

⚠ Common exam trap

It's easy for candidates to confuse `kubeadm certs renew all` with `kubeadm upgrade apply`, thinking an upgrade is required to renew certificates, when in fact the dedicated renew command exists and is the correct tool for certificate-only renewal without changing cluster version.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubeadm certs renew all

`kubeadm certs renew all` is the dedicated command to renew all PKI certificates in a kubeadm-managed cluster. It regenerates each certificate using the existing CA key, updating the certificate files in `/etc/kubernetes/pki/` without restarting control plane components; a manual restart or kubelet reload is required afterward.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubeadm certs renew apiserver

    Why it's wrong here

    While this command is valid, it specifically targets and renews only the apiserver certificate located in the PKI directory. It does not affect other essential control plane certificates, such as those for the controller-manager, scheduler, or etcd, leaving them prone to expiration.

  • ✗

    kubeadm certs check-expiration

    Why it's wrong here

    This command is a diagnostic tool used to view the remaining validity period of all kubeadm-managed certificates. It only displays the current expiration dates and does not perform any write or renewal operations on the certificate files.

  • ✓

    kubeadm certs renew all

    Why this is correct

    This is the correct command to renew all control plane certificates managed by kubeadm at once. It automatically regenerates the certificates under the PKI directory and updates the embedded client certificates within the administrative kubeconfig files.

  • ✗

    kubeadm upgrade apply

    Why it's wrong here

    Although upgrading a cluster with this command automatically renews certificates that are close to expiration as a side effect, it is not the dedicated command for certificate renewal. Using it solely for renewal is inefficient and risky, as it triggers a full control plane version upgrade.

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.