You can know Kubernetes cold and still lose points on exam day — not because of the questions, but because of the logistics. Every year, candidates fail environment checks, get their exam paused for looking away from the screen, or waste ten minutes hunting for documentation they were allowed to use the whole time. The five CNCF Kubernetes exams — CKA, CKAD, CKS, KCNA, and KCSA — that together earn you the coveted KubeAstronaut title all run on the same proctoring platform and share the same rules. Learn those rules once and they apply to your entire certification journey.
This guide walks through exactly how CNCF exams work in 2026: who administers them, what the remote-proctored environment looks like, which documentation you’re allowed to open, the identity and workspace requirements, the retake policy, and how results are delivered. It’s the operational playbook that complements the technical study — so nothing on exam day catches you off guard.
A note on policy: exam logistics evolve. The CNCF, the Linux Foundation, and the exam vendor periodically update the platform, the allowed documentation list, and the interface. Always read the official Candidate Handbook and the “Important Instructions” page for your specific exam before you sit — treat this article as orientation, not a substitute for the current official rules.
Who Runs the Exams: CNCF, the Linux Foundation, and PSI
It helps to understand the three parties involved:
- The CNCF (Cloud Native Computing Foundation) owns the certifications and defines the curriculum for each exam.
- The Linux Foundation administers the program — this is where you register, schedule, and access your candidate portal.
- PSI is the proctoring and exam-delivery vendor. The exam itself runs inside a secure, browser-based environment with a live remote proctor watching over webcam, microphone, and screen share.
All five exams are online and remotely proctored. There are no testing centers to visit — you take them from your own home or office, which means you are responsible for meeting the environment requirements.
The Two Exam Formats
The five exams split into two very different formats, and knowing which is which shapes how you prepare for the day.
| Exam | Format | Duration | Style | CKA required first? |
|---|---|---|---|---|
| KCNA | Multiple choice | 90 min | Closed-book | No |
| KCSA | Multiple choice | 90 min | Closed-book | No |
| CKAD | Performance-based | 2 hours | Hands-on cluster tasks | No |
| CKA | Performance-based | 2 hours | Hands-on cluster tasks | No |
| CKS | Performance-based | 2 hours | Hands-on cluster tasks | Yes (active CKA) |
- KCNA and KCSA are entry-level, multiple-choice exams (around 60 questions in 90 minutes). They are closed-book — no documentation is allowed.
- CKA, CKAD, and CKS are performance-based: you’re dropped into real Kubernetes clusters via a browser terminal and asked to solve roughly 15–20 weighted tasks in two hours. These exams do allow limited official documentation.
- CKS has a hard prerequisite: you must hold an active CKA certification before you’re permitted to sit it. Plan your KubeAstronaut order accordingly.
Passing scores differ by exam and are published on each exam’s page — the performance-based exams generally sit in the 66–67% range, and the multiple-choice exams around 75%. Always confirm the current threshold on the official exam page.
Inside the Remote-Proctored Environment
When your appointment begins, you launch the exam through the PSI secure browser, and a proctor connects. Here’s what the check-in and monitoring involve:
- Identity verification — you must present a valid, non-expired, government-issued photo ID whose name matches your Linux Foundation profile exactly. A passport or driver’s license is standard.
- Room and desk scan — you’ll be asked to show your surroundings via webcam, including your desk surface. The area must be clear: no notes, no second phone, no books, no papers, no extra monitors in use.
- Continuous monitoring — your webcam and microphone stay on for the entire exam, and your screen is shared. The proctor can see and hear you throughout.
- You must stay in frame and stay silent. Looking off-screen for extended periods, reading aloud, someone else entering the room, or reaching off-camera can all trigger a warning or a pause.
Hardware and workspace requirements
- A reliable computer running a supported OS with Chrome or a Chromium-based browser and the PSI secure-browser components installed.
- A working webcam and microphone (external webcams help with the room scan).
- Stable internet — a wired connection is safer than Wi-Fi for a two-hour performance exam.
- A quiet, private, well-lit room you can occupy alone for the full duration plus check-in.
- A single monitor. Dual-monitor setups must be disabled; the second screen has to be unplugged, not just switched off.
Run the exam vendor’s compatibility/system check days in advance — not an hour before. Corporate laptops with locked-down security policies frequently fail the secure-browser install, and you don’t want to discover that during check-in.
What Documentation You’re Allowed to Use
This is the single most misunderstood part of CNCF exams. The performance-based exams are open-book — but only to a strictly limited set of official sites, opened in a documentation tab within the exam environment. You may not browse the open internet, use search engines, or open your own notes.
For the hands-on exams, the allowed documentation generally includes:
- CKA and CKAD: the official Kubernetes documentation at
kubernetes.io/docs, the Kubernetes blog atkubernetes.io/blog, and (for the relevant exams) the Helm documentation. - CKS: the Kubernetes documentation plus a small set of tool-specific docs relevant to the security curriculum — historically the docs for tools like Trivy, Falco, and AppArmor.
KCNA and KCSA allow no documentation at all — they are closed-book multiple-choice exams.
Because the allowed-domains list is periodically updated, verify it on the official “Important Instructions” page for your exam shortly before you sit. The practical takeaway is the same either way: don’t rely on Googling during the exam, because you can’t. Build your recall so the docs are a reference for exact syntax, not a crutch for concepts.
A pro tip that pays off on CKA/CKAD/CKS: learn to navigate kubernetes.io/docs fast. Know where the YAML examples for Pods, Deployments, Services, RBAC, and NetworkPolicies live, and lean on kubectl explain and kubectl create ... --dry-run=client -o yaml to generate manifests instead of copying from docs by hand.
The Exam Interface and Working Efficiently
For the performance-based exams, the interface is a browser window with a terminal and an embedded documentation browser, plus a question panel. A few things that trip people up:
- Copy/paste works, but the shortcuts differ inside the remote terminal (often
Ctrl+Shift+C/Ctrl+Shift+V). Practice with these so you’re not fumbling. - You control multiple clusters. Each task specifies a
kubectl config use-contextcommand to switch to the correct cluster — run it every time, or you’ll solve the task on the wrong cluster and score zero. - Tasks are weighted. Each is worth a different percentage, shown next to it. Triage: bank the high-value, quick wins first and flag hard ones to revisit.
- A notepad is provided for jotting task numbers you want to return to.
- Set up your shell early. In the first minute, configure a
kubectlalias and completion — for examplealias k=kubectland the standard bash-completion setup — to save keystrokes across every task.
We cover the terminal, kubectl, and speed techniques in depth in our guide to mastering the Kubernetes exam terminal — worth reading before any performance-based attempt.
Retakes, Results, and Certification Validity
Some of the most reassuring rules are the ones candidates don’t know about until after they’ve stressed unnecessarily.
- Free retake included. Each CNCF exam registration includes one free retake. If you don’t pass the first time, you can schedule a second attempt at no extra cost — a genuine safety net that takes the pressure off your first sit.
- Results are not instant. Even though the performance exams are hands-on, they aren’t graded live. Expect your result by email, typically within about 24 hours of finishing.
- Certifications are valid for 2 years. Each CNCF certification is valid for two years from the date you pass, after which you’ll need to recertify to keep it active. For KubeAstronaut aspirants juggling five certs, this matters — see our Kubernetes certification renewal guide for how to keep them all current.
- Scheduling flexibility. You can typically reschedule an appointment up to a cutoff before the start time; check the current window in your candidate portal so you don’t forfeit the sitting.
An Exam-Day Checklist for Every CNCF Exam
Run this list before every one of your five KubeAstronaut exams:
| When | Action |
|---|---|
| Days before | Run the system/compatibility check; install the secure browser |
| Days before | Confirm your ID name matches your Linux Foundation profile exactly |
| Days before | Verify the current allowed-documentation list for your exam |
| Night before | Clear your desk and room; test webcam, mic, and internet |
| 30 min before | Close all other apps; disable the second monitor physically |
| At check-in | Have ID ready; expect a room scan; stay calm and follow the proctor |
| First 2 min (hands-on) | Set alias k=kubectl, enable completion, note the docs tab |
| Every task (hands-on) | Run the kubectl config use-context line first |
| Throughout | Stay in frame, stay silent, bank easy points first |
How to Walk In Genuinely Ready
Knowing the rules removes the surprises, but confidence on exam day comes from having already worked in the exact conditions you’ll face. For the hands-on exams especially, the biggest gap between “I know Kubernetes” and “I passed” is comfort operating a live cluster under a two-hour clock, in a browser terminal, switching contexts and racing weighted tasks.
That’s the entire premise of the KubeAstronaut Mock Exam Bundle. It bundles realistic, time-boxed mock exams for all five certifications — performance-based labs in real clusters for CKA, CKAD, and CKS, and full multiple-choice sets for KCNA and KCSA — so you rehearse the format, the pacing, and the context-switching long before the real thing. Practicing under the same constraints is what turns exam-day logistics from a threat into a formality.
To build your broader plan around these logistics, read the KubeAstronaut path guide for the optimal exam order and timeline, check whether the full journey fits your goals in is KubeAstronaut worth it in 2026, and map the topics across all five exams with the KubeAstronaut curriculum map. If you want to practice for free first, our open-source CK-X exam simulator recreates the terminal experience.
Frequently Asked Questions
Are CNCF Kubernetes exams open-book?
Partially. The performance-based exams (CKA, CKAD, CKS) let you open a strictly limited set of official documentation — primarily kubernetes.io/docs plus a few tool-specific sites for CKS — inside the exam environment. You cannot use search engines, your own notes, or the open internet. KCNA and KCSA are closed-book multiple-choice exams with no documentation allowed.
Can I use a second monitor during the exam?
No. Performance and multiple-choice exams alike require a single monitor. Any additional display must be physically disconnected, not merely turned off, and the proctor will verify this during check-in.
What happens if I fail a CNCF exam?
Every registration includes one free retake. If you don’t pass on the first attempt, you can schedule a second sitting at no additional cost, giving you a built-in safety net. Use the first attempt as a serious try, knowing the retake is there if you need it.
How long until I get my results?
CNCF exams are not graded live. Results are typically emailed within about 24 hours of completing the exam, even for the hands-on performance exams.
Do I need CKA before taking CKS?
Yes. CKS requires an active CKA certification. You must pass CKA (and keep it valid) before you’re allowed to sit CKS. The other four exams have no prerequisites, so many candidates take KCNA, then CKA, before attempting the security exams.
How long are the certifications valid?
Each CNCF certification is valid for two years from your pass date. To maintain KubeAstronaut status, you’ll need to recertify each credential before it expires.
What documentation is allowed for the CKS exam specifically?
CKS historically permits the Kubernetes documentation plus a handful of security-tool docs used in the curriculum, such as Trivy, Falco, and AppArmor. Because this list can change, confirm the exact allowed domains on the official Important Instructions page for CKS right before your exam.
Key Takeaways
- All five KubeAstronaut exams are online, remotely proctored through the Linux Foundation and PSI — no test centers.
- CKA, CKAD, CKS are 2-hour, hands-on performance exams; KCNA, KCSA are 90-minute, closed-book multiple-choice exams.
- Performance exams are open to limited official docs only (
kubernetes.io/docsand a few others); multiple-choice exams allow no docs. Verify the current list before sitting. - Expect strict environment rules: valid photo ID, a room scan, a clear desk, a single monitor, and continuous webcam/mic monitoring.
- On hands-on exams, always run the context-switch command, set up a
kubectlalias early, and bank high-weight tasks first. - Every exam includes one free retake, results arrive in ~24 hours, and certifications are valid for 2 years.
Master the logistics once and they serve you across all five exams. Pair that operational confidence with realistic, full-format KubeAstronaut mock exams, and every sitting on the road to KubeAstronaut becomes about the Kubernetes — not the surprises.