CKA Practice Question: Cluster Architecture, Installation and Configuration
Your kubeadm cluster was initialized with default certificates. You need to check the expiration of the API server certificate and renew it if necessary. Which TWO commands are appropriate? (Choose TWO.)
⚠ Common exam trap
Many exam-takers confuse `kubeadm certs` subcommands with `kubectl` commands, mistakenly thinking `kubectl config view` or `kubectl cluster-info` can reveal certificate expiration, when in fact only `kubeadm` has direct access to the PKI files on the control plane node.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubeadm certs renew all
Option B, `kubeadm certs check-expiration`, is correct because it is the dedicated kubeadm subcommand that reads the certificates stored in /etc/kubernetes/pki (and the kubeconfig files in /etc/kubernetes) and prints each certificate's expiration date, residual time, and whether it is CA or not, which directly satisfies the requirement to check expiration. Option A, `kubeadm certs renew all`, is correct because it renews every certificate managed by kubeadm, including the API server certificate (apiserver.crt), and is the standard way to renew them when they are expired or near expiry. Option C, `kubectl config view`, only displays the kubeconfig context, cluster, and user settings and reveals nothing about certificate expiration dates. Option D, `kubeadm upgrade plan`, checks available Kubernetes version upgrades and component compatibility, not certificate expiry. Option E, `kubectl cluster-info`, merely shows the addresses of the control plane and core services, so it cannot check or renew certificates.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
kubeadm certs renew all
Why this is correct
This command performs a unified renewal of every Kubernetes certificate that kubeadm manages, including the API server, controller-manager, scheduler, and etcd certificates, plus the client certificates in kubeconfig files. It is the go-to action when certificates were created with default validity and need refreshing. After running it, the control plane components must be restarted to start using the new certificates.
- ✓
kubeadm certs check-expiration
Why this is correct
This command inventories all certificates under the kubeadm-managed PKI directory and prints their expiration dates, remaining validity period, and renewal status in a table. It is a read-only diagnostic that tells you exactly which certificates are nearing expiry, such as the admin.conf client certificate or the etcd server certificate. As a correctness point, it validates that your cluster's certificate state is being monitored, but it does not perform the actual renewal.
- ✗
kubectl config view
Why it's wrong here
This command outputs the merged kubeconfig information from multiple files, showing cluster, context, and user stanzas along with the paths to client certificates and keys. It does not decode those certificates or reveal their expiration timestamps, and it has no capability to renew or modify certificates. Therefore it is irrelevant for verifying or managing certificate expiry in a kubeadm cluster.
- ✗
kubeadm upgrade plan
Why it's wrong here
This command evaluates which Kubernetes version upgrades are available and lists the manual steps required for an upgrade, including a preflight check of the cluster's health. While it may warn about expiring certificates during the preflight, its primary purpose is upgrade planning, not certificate lifecycle management. It will never renew certificates or give you a per-certificate expiration breakdown, so it is not the right tool for this task.
- ✗
kubectl cluster-info
Why it's wrong here
This command displays connection details for the control plane endpoints, such as the Kubernetes API server address and the CoreDNS service endpoint. It is purely a connectivity and cluster identity diagnostic, with zero awareness of the internal PKI that secures communication between components. Thus it cannot help you check or renew the default certificates created by kubeadm.
Go deeper
Related to this question
Learn chapter
Services and Networking Fundamentals
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.