← All Certifications
Kubernetes

Kubernetes CKAD Certification

CKAD · Performance-based

Last updated: March 31, 2026

Exam Syllabus & Domains

The Kubernetes CKAD certification exam covers the following domains. Focus your training time proportionally to each domain's weight.

Domain 1 20%

Application Design and Build

  • 1.1 Define, build and modify container images
  • 1.2 Choose and use the right workload resource (Deployment, DaemonSet, CronJob, etc.)
  • 1.3 Understand multi-container Pod design patterns (sidecar, init, adapter, ambassador)
  • 1.4 Utilize persistent and ephemeral volumes
Dockerfile Best Practices (Multi-Stage Builds)OCI Image SpecificationInit Containers for Setup TasksSidecar Containers (Logging, Proxy)Ambassador and Adapter PatternsJobs and CronJobs for Batch WorkVolume Types (emptyDir, PVC, configMap, secret)Container Resource ManagementImage Pull Policies (Always, IfNotPresent, Never)
Domain 2 20%

Application Deployment

  • 2.1 Use Kubernetes primitives to implement common deployment strategies
  • 2.2 Understand Deployments and how to perform rolling updates
  • 2.3 Use Helm package manager to deploy existing packages
  • 2.4 Kustomize for configuration management
Rolling Update Strategy (maxSurge, maxUnavailable)Recreate Deployment StrategyBlue-Green Deployment via ServicesCanary Deployments with LabelsHelm Charts (install, upgrade, rollback)Helm Values and TemplatesKustomize Overlays and BasesDeployment Revision Historykubectl rollout Commands
Domain 3 15%

Application Observability and Maintenance

  • 3.1 Understand API deprecations
  • 3.2 Implement probes and health checks
  • 3.3 Use built-in CLI tools to monitor Kubernetes applications
  • 3.4 Utilize container logs
  • 3.5 Debugging in Kubernetes
Liveness Probes (HTTP, TCP, Exec)Readiness Probes for Traffic ControlStartup Probes for Slow Containerskubectl top for Resource Metricskubectl logs for Container Outputkubectl exec for Interactive DebuggingAPI Version Deprecation PolicyEphemeral Debug ContainersApplication Self-Healing Mechanisms
Domain 4 25%

Application Environment, Configuration & Security

  • 4.1 Discover and use resources that extend Kubernetes (CRDs, Operators)
  • 4.2 Understand authentication, authorization and admission control
  • 4.3 Understand requests, limits, and quotas
  • 4.4 Understand ConfigMaps and Secrets
  • 4.5 Define resource requirements and SecurityContexts
  • 4.6 Create and consume Secrets
ConfigMaps (envFrom, volumeMount)Secrets (Opaque, TLS, docker-registry)SecurityContext (runAsUser, runAsNonRoot, capabilities)PodSecurityStandards (Restricted, Baseline, Privileged)ResourceQuota and LimitRangeServiceAccounts and RBAC for ApplicationsCustom Resource Definitions (CRDs)Operator PatternAdmission ControllersPod Security Admission
Domain 5 20%

Services & Networking

  • 5.1 Demonstrate basic understanding of NetworkPolicies
  • 5.2 Provide and troubleshoot access to applications via services
  • 5.3 Use Ingress rules to expose applications
Service Types (ClusterIP, NodePort, LoadBalancer)Ingress Resources and ControllersIngress TLS TerminationNetworkPolicy (Ingress/Egress Rules)DNS for Service Discovery (svc.cluster.local)Headless Services for StatefulSetsExternalName ServicesPort Forwarding with kubectl port-forwardEndpoint Slices

Where to Focus Your Study Time

Domains with higher weight have more exam questions — allocate your study hours accordingly.

D1 Application Design and Build
20%
D2 Application Deployment
20%
D3 Application Observability and Maintenance
15%
D4 Application Environment, Configuration & Security
25%
D5 Services & Networking
20%

Study Tips

Free Study Resources

๐Ÿ“‹

Study Roadmap

Week-by-week study plan with free resources

โœ…

Study Tracker

Track objective completion with progress dashboard

๐Ÿ’ฐ

Cost Calculator

Total cost breakdown and ROI analysis

๐Ÿงช

Practice Quiz

Test your knowledge with free practice questions

Practice Quiz

Test your knowledge before the exam with our free practice quiz.

Take the Kubernetes CKAD Practice Quiz

Get the Kubernetes CKAD Study Planner

Fillable PDF with 10-week schedule, domain trackers, flashcard templates, progress tracking, and quick reference sheets. Available in Standard, ADHD-Friendly, Dark Mode, and 4-Format Bundle.

Get the Study Planner — $5.99

Also available as a 4-Format Bundle for $15.99

CyberFolio

Earned your certs? Show employers.

Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.

Build Your Portfolio →

Free Training Resources

Use these free tools to support your Kubernetes CKAD certification training:

Frequently Asked Questions

What is the Kubernetes CKAD certification?

The Kubernetes CKAD (CKAD) is a professional IT certification that validates your knowledge and skills in the exam domains covered. It is recognized globally by employers and is a valuable credential for career advancement in cybersecurity and IT.

What does the Kubernetes CKAD certification syllabus cover?

The Kubernetes CKAD exam syllabus covers Performance-based. Each domain is weighted differently, so focus your training on higher-weighted domains first. Review the complete domain breakdown above for objectives and key concepts.

How should I study for Kubernetes CKAD?

Create a structured study plan covering all exam domains, use practice tests to identify weak areas, and review key concepts regularly. A fillable study planner can help you organize your training with weekly schedules and progress tracking.

How long does it take to prepare for Kubernetes CKAD?

Preparation time varies by experience level. Most candidates spend 8-12 weeks of dedicated training. Using a structured study planner with domain-by-domain breakdown helps ensure you cover all certification objectives efficiently.