Other Certifications · Mirantis · Docker Certified Associate

Docker Certified Associate

The Docker Certified Associate (DCA) is the vendor credential for core Docker and container fundamentals — not Kubernetes, not a specific cloud, just Docker itself: building images correctly, running Swarm-mode orchestration, wiring up networking and storage, and locking a container pipeline down. It predates this course's own containers & orchestration lesson and Docker tool page by several years, and it has lived through a genuine ownership change in that time: Docker, Inc. split its business in November 2019, and the enterprise half DCA's content was largely built around — Swarm at scale, Universal Control Plane, Docker Trusted Registry — went to a different company, Mirantis. What follows is a full profile of the exam as it has been documented, but read the second section before you trust anything else on this page: an explicit flag to verify who administers this exam today, and whether it's still being offered at all, before you spend a cent registering for it.

☺ Explain it like I'm 10

Imagine a driving-test center that, partway through its life, sold off half its business — the trucks, the freight-hauling exams, the big commercial-license program — to a totally different company, while keeping the cars and the everyday license for itself. If you ask "who do I call to book the truck exam now," the honest answer is "probably the company that got the trucks — but go check, because when a business gets split in half, its programs don't always keep running exactly the way they used to, and some quietly stop running at all." That's this page. The exam's subject matter — building images, running containers at scale, wiring up networking and storage — is still real and still worth knowing cold. Who currently hands out the certificate for knowing it is the part you have to double-check yourself, today, not trust from a page like this one.

🦫🐙Your hosts for this topic: Benny the Beaver & Olly the Octopus — Benny has built more Docker images than anyone in the Guild on the Docker page, and DCA's image, registry, and Dockerfile domain is basically his exam; Olly keeps every container talking to the others in containers & orchestration, and DCA's orchestration domain — Docker Swarm specifically, not Kubernetes — is his.

What the DCA is, and who it's for

☺ Like you're 10: A 90-minute, 55-question, closed-book multiple-choice exam about Docker specifically — no live terminal, unlike the CKA, even though almost everything it asks about is operational.

Docker, Inc. first opened the Docker Certified Associate for registration in late 2018 and took it to general availability in early 2019, as the company's own entry-level credential for the platform it created. Unlike the CKA, it is entirely knowledge-based: 55 multiple-choice questions in 90 minutes, delivered online with remote proctoring, no live daemon in front of you and nothing graded on end state. That's a real gap between what the exam tests and how it tests it — the six domains below are almost entirely operational skills (build this, wire this network, mount this volume, roll this service update), but the exam checks whether you can recognize the correct command or concept from a list, not whether your fingers can type it correctly under a clock.

It targets people who build and ship containers day to day and the operators who keep a Docker or Swarm fleet running underneath them — less a Kubernetes-cluster-administrator credential than a "do you actually know Docker itself, cold" one. Docker's own historical candidate guidance recommended 6–12 months of hands-on Docker experience before sitting it, though nothing enforces that formally; there is no prerequisite exam or credential required to register.

ItemWhat has historically been published
FormatOnline, remotely proctored, closed-book — 55 multiple-choice questions, no hands-on lab component
Duration90 minutes
Passing scoreNot consistently published as a fixed percentage — treat any specific number you read anywhere, including this page, as unconfirmed
PriceHistorically around USD $195 — verify this before you trust it; see the section below on why this program's pricing and even its purchasability are worth double-checking specifically
PrerequisitesNone formally required; Docker's own historical guidance recommended 6–12 months of hands-on Docker experience first
Validity2 years from the date you pass
Administering bodyOriginally Docker, Inc.; commonly reported to now be Mirantis — see the next section before you assume either is currently correct

A program that changed hands: Docker, Inc. → Mirantis — verify before you spend anything

☺ Like you're 10: In November 2019, Docker sold the entire enterprise half of its business — including the Swarm-at-scale tooling this exam is built around — to a different company, Mirantis. Whether Mirantis still runs this exact certification today is the first thing to check, not the last.

This part is well documented and not in dispute: in November 2019, Docker, Inc. sold its Docker Enterprise platform business — Docker Enterprise Engine, Universal Control Plane (UCP), and Docker Trusted Registry (DTR), along with the enterprise customer contracts attached to them — to Mirantis. Docker, Inc. kept Docker Desktop, Docker Hub, Compose, and the developer-facing CLI tooling, and re-focused as a smaller company built around individual developers rather than enterprise container platforms. Mirantis subsequently rebranded the products it acquired: UCP became Mirantis Kubernetes Engine (MKE), and DTR became Mirantis Secure Registry (MSR) — names you'll see on newer study material that older DCA guides won't mention at all.

DCA's own domain list — Swarm orchestration at production scale, an enterprise registry, installation and configuration of a multi-node platform — lines up far more closely with the half of the business that went to Mirantis than with the Docker Desktop and Docker Hub half that stayed with Docker, Inc. Consistent with that, Mirantis's own training portal has been the most commonly reported home for DCA registration since the split. That is the most defensible current answer this page can give you, and it is exactly the kind of fact this section exists to make you re-check rather than accept.

Before November 2019: one company Docker, Inc. Engine · Swarm · UCP · DTR Docker Hub · Docker Desktop · DCA the split Docker, Inc. — kept Docker Desktop Docker Hub, Compose developer-facing CLI tooling Mirantis — acquired Swarm enterprise engine UCP → MKE, DTR → MSR DCA cert (as commonly reported) ⚠ confirm this is still accurate before you register
⚠ Verify who runs this exam, and whether it's still offered, before you register

Two separate things need checking, not one. First: who administers DCA today. The most defensible current answer is Mirantis, via its training portal at training.mirantis.com — but confirm that page still lists an active, purchasable Docker Certified Associate exam before you plan around it; specific certification-page URLs on training portals move more often than root domains do. Second, and more important: whether the program is still actively accepting new candidates at all. Mirantis has since shifted its own product strategy further toward Kubernetes — Mirantis Kubernetes Engine's own architecture has moved in that direction over successive versions — which is a reasonable prompt to double-check that a Swarm-centric associate exam is still a current priority for the company holding it, not a signal either way on its own. Community reports on this specific point have been mixed over the past few years. Treat "is this exam currently for sale" as the very first fact to confirm, before price, before format, before anything else on this page.

The official domain breakdown

☺ Like you're 10: Six topics, and — like the CKA and unlike the Terraform Associate — Docker's own exam guide did publish a percentage weight for each one.

Docker, Inc.'s own DCA exam guide published six domains with explicit weights summing to 100%. These numbers have been stable and widely corroborated across the program's lifetime, though — consistent with everything above — confirm they're still the current structure with whoever administers the exam today before you build a study plan around them down to the percentage point.

🐙Orchestration
25%
🦫Image Creation, Management & Registry
20%
🏗️Installation and Configuration
15%
🌐Networking
15%
🔒Security
15%
🗄️Storage and Volumes
10%

Note the shape: Orchestration alone is 25%, tied with Image/Registry work as the two domains worth the most study time, and together they're 45% of the exam — nearly half. The wording below is a study-oriented reconstruction of Docker's long-published domain structure, not a verbatim quote; confirm the exact current sub-bullet text with whoever's running the exam before treating any single phrase as exam-verbatim.

Orchestration: this exam means Swarm, not Kubernetes

☺ Like you're 10: The single biggest surprise for anyone studying this after this course's own Kubernetes-heavy material: DCA's orchestration domain is Docker Swarm — a different, older, simpler orchestrator — not Kubernetes at all.

This is the distinction that trips up the most people coming from this course specifically. Containers & orchestration, the CKA, and the CKAD are all Kubernetes-first. DCA's 25%-weighted Orchestration domain is not — it's built around Docker Swarm mode, Docker's own simpler, built-in orchestrator: initializing a swarm, joining nodes as managers or workers, deploying multi-container applications as services and stacks, rolling updates, scaling, and swarm-native secrets. If your only orchestration experience is kubectl, budget real study time here — the concepts rhyme (declarative desired state, a control plane reconciling it) but the commands, objects, and vocabulary are entirely different.

# initialize a swarm on a manager node, then join workers/managers from other hosts
docker swarm init --advertise-addr 10.0.0.5
docker swarm join-token worker              # prints the join command to run on worker nodes
docker swarm join-token manager             # prints the join command for additional managers

# a "service" is Swarm's unit of deployment — a desired-state spec Swarm reconciles across the cluster
docker service create --name web --replicas 3 --publish 8080:80 nginx:1.27
docker service ls
docker service ps web                       # which node is each of the 3 replicas actually running on?

# rolling update: Swarm updates instances in controlled batches, not all at once
docker service update --image nginx:1.28 --update-parallelism 1 --update-delay 30s web
docker service scale web=5                  # imperative scale, no separate autoscaler object

# a "stack" deploys a whole multi-service application from a Compose file, Swarm-native
docker stack deploy -c docker-compose.yml myapp
docker stack services myapp

# secrets are swarm-native, encrypted at rest in the raft log, mounted as in-memory files — not env vars
docker secret create db_password ./db_password.txt
docker service create --name api --secret db_password myapp/api:1.4

The overlay networking that makes multi-host Swarm services reachable, and the routing mesh that lets any node in the swarm answer a published port for a service running elsewhere, are covered in the networking section below.

Images, Dockerfiles, and registries — what already overlaps with this course

☺ Like you're 10: This domain is the one you've likely already half-studied — building good images and knowing where they live is core material this course covers whether or not you're chasing a certification.

The 20%-weighted Image Creation, Management, and Registry domain is the least surprising of the six if you've already worked through the Docker tool page: Dockerfile instructions and layer caching, multi-stage builds to keep a shipped image small, tagging conventions, pushing to and pulling from a registry, and the difference between a public registry like Docker Hub and a private one. On the enterprise side, this domain is also where Docker Trusted Registry — now Mirantis Secure Registry — questions have historically lived: image scanning, replication between registries, and role-based access to repositories.

The exam expects you to know the practical difference between a resource-style build artifact (an image, immutable once built and tagged) and the registry that stores it, plus the vocabulary around image signing and provenance that this course covers in more depth than DCA's own guide does at supply-chain security & SBOM. Full Dockerfile syntax, multi-stage build patterns, and layer-cache mechanics are already covered end to end on the Docker tool page — this domain doesn't need a separate code sample here because that page's is the same material.

Installation, networking, security, and storage — the rest of the operational core

☺ Like you're 10: The four remaining domains, worth 55% combined — how you set the engine up, how containers reach each other, how you lock things down, and where data actually lives when a container stops.

Installation and Configuration (15%) covers installing and configuring the Docker Engine itself, editing daemon behavior through /etc/docker/daemon.json, and — on the enterprise side — backing up and restoring a Swarm's raft consensus data, since losing every manager node without a backup means losing the cluster's entire state.

Networking (15%) covers Docker's built-in network drivers: the default bridge network for single-host containers, user-defined bridge networks for better container-to-container DNS resolution, and — for Swarm specifically — the overlay driver that lets containers on different physical hosts reach each other, plus the routing mesh, which lets a published port answer on every node in the swarm regardless of which node the container actually landed on.

docker network create --driver overlay --attachable app-net
docker service create --name api --network app-net --replicas 3 myapp/api:1.4
# any node in the swarm can now answer requests on api's published port —
# that's the routing mesh, not a load balancer you configured yourself

Security (15%) covers Docker Content Trust for signing and verifying images, running containers as a non-root user, the isolation Linux namespaces and cgroups actually provide (and don't — a container is not a VM), and, on the enterprise side, role-based access control inside UCP/MKE.

export DOCKER_CONTENT_TRUST=1        # now docker push/pull require and verify signatures
docker push myrepo/app:1.2           # fails closed if the image isn't signed by a trusted key

Storage and Volumes (10%), the smallest domain, covers the three ways data survives (or doesn't) past a container's lifetime: named volumes managed by Docker, bind mounts to a specific host path, and tmpfs mounts that never touch disk at all.

docker volume create app-data
docker run -d --name db -v app-data:/var/lib/postgresql/data postgres:16
docker run -d --name web -v $(pwd)/html:/usr/share/nginx/html:ro nginx:1.27   # bind mount, host path
docker volume inspect app-data       # where does Docker actually keep this on the host?
◆ Key idea

Two of DCA's six domains — Installation and Storage — barely exist as hands-on topics in this course's own Kubernetes-first material, because Kubernetes abstracts a node's local container-runtime installation and a CSI driver's storage class away from anything you configure by hand day to day. That's not a gap in this course; it's the same substrate-versus-platform boundary the CKA page draws between operating a cluster and building on top of one — except DCA sits one layer further down than even the CKA does, at the single-engine or single-Swarm level Kubernetes itself is usually running on top of.

How to prepare using this course

☺ Like you're 10: Two lessons cover most of it directly; the Swarm-specific half has no dedicated page here and is the part you'll need to learn mostly from hands-on practice and the vendor's own material.

DCA domainStudy here
Orchestration · 25%No dedicated Swarm page exists in this course — Containers & orchestration teaches the same declarative-reconciliation concepts through Kubernetes instead; treat that as the mental model and layer Swarm's specific commands (shown above) on top through hands-on practice
Image Creation, Management & Registry · 20%Docker — Dockerfile syntax, multi-stage builds, layer caching, tagging, in full · Supply-Chain Security & SBOM for signing and provenance
Installation and Configuration · 15%Docker's architecture section (Engine, containerd, runc) for the pieces being installed and configured
Networking · 15%Containers & orchestration for the general container-networking model; the overlay/routing-mesh specifics above are Swarm-only and not duplicated elsewhere in this course
Security · 15%Secrets & Credential Management for the secrets-handling half · Shift-Left Security for DevOps for the broader posture Content Trust and image scanning sit inside
Storage and Volumes · 10%Docker for the underlying image-and-container model volumes attach to; this course otherwise covers storage at the Kubernetes PV/PVC layer rather than the raw Docker-volume layer this domain tests
Speed & recallFlashcards · Glossary

The honest gap: this course was built Kubernetes-forward, so roughly half of DCA's weight — Orchestration and a chunk of Networking — has no direct page here. The other half — images, registries, security, and the Docker Engine fundamentals underneath everything — is already well covered. Plan to spend real hands-on time with a throwaway multi-node Swarm (three small VMs or cloud instances are enough) running the exact commands in the Orchestration section above; there's no substitute for having actually typed docker service update against a real cluster.

Exam logistics — and why verifying them matters more here than on any other cert in this course

☺ Like you're 10: Every certification's details drift over time. This one has drifted further than most, because the company running it changed entirely at least once.

ItemWhat to check, and why
Whether the exam is still offered at allThe single most important check on this page — confirm an active, purchasable listing exists before checking anything else below
Administering body and delivery platformMost recently and commonly reported as Mirantis, via its training portal — confirm current ownership directly rather than assuming this page is still accurate
PriceHistorically around $195; confirm the current fee, and whether it now follows Mirantis's own broader training-catalog pricing rather than Docker, Inc.'s original figure
Question count, duration, passing score90 minutes and 55 questions have been consistently reported historically; passing score has never been consistently published as a fixed number by any administering party — treat any specific percentage as unconfirmed
Domain weights and contentThe six domains and weights above are Docker, Inc.'s long-published structure; confirm they haven't been revised or replaced under Mirantis's stewardship
Badge issuance and validityHistorically a 2-year validity window with a digital badge on passing; confirm current terms with whoever currently administers the program
⚠ Verify this before you book — more than any other certification on this site

Every fact on this page is a snapshot of a program that has already changed hands once and may have changed again since. This site is independent and unofficial. Before you pay for anything, confirm current details directly at Mirantis's training portal, training.mirantis.com — and if that trail goes cold, search for whether Docker, Inc. itself has reintroduced any certification program of its own, since the 2019 split means either answer is plausible. Do not register anywhere, or study from anyone's paid material, until you've confirmed the exam is currently, actively being sold by the party you're paying.

Where it sits, and who should consider it

☺ Like you're 10: A fast, narrow, single-tool exam like the Terraform Associate — but with a real question mark over its current availability that neither of the other two certifications this course covers has.

Of the certifications profiled in depth across this course, DCA is closest in shape to the Terraform Associate: knowledge-based, one vendor's tool, no hands-on lab component, roughly an hour and a half rather than the CKA's two hours of live cluster work. What sets it apart isn't its format — it's the program-status uncertainty this whole page has flagged, which neither Terraform Associate nor the CKA currently carries to the same degree.

Docker Certified AssociateTerraform AssociateCKA
QuestionDo you know Docker itself — images, Swarm, networking, security, storage?Do you know Terraform's syntax and workflow?Can you actually run a Kubernetes cluster?
FormatKnowledge-based, multiple choiceKnowledge-based, multiple choice100% performance-based, live clusters
ScopeOne tool, Swarm-mode orchestrationOne toolOne platform, any tooling around it
Program stabilityAdministering body has already changed once (Docker, Inc. → Mirantis); current availability unconfirmedVersion has changed (003→004); program structure itself stableCurriculum weights revised periodically; program structure stable

Consider it if: your organization runs Docker Swarm in production — it's a smaller footprint than Kubernetes today but far from extinct, especially in smaller shops that never needed Kubernetes' full complexity — and you want a formal check on Docker fundamentals broader than what a Kubernetes-only role would cover. Consider skipping it if: your organization runs Kubernetes rather than Swarm, in which case the CKA or CKAD will transfer far more directly to your actual job and to more employers; or if, after checking, you find the program is no longer actively administered — in which case treat this page as a study reference for genuinely useful Docker knowledge rather than exam prep, and put your certification budget toward the certifications page's other options instead.

🎬 At the Ship-It Guild
🦫

Benny the Beaver: I just tried to link the DCA's registration page and hit three different old URLs before one of them even loaded.

🐙

Olly the Octopus: That's what happens when a program moves houses, Benny. The furniture doesn't always follow the address change.

🐘

Ellie the Elephant: I've got the domain weights on record, at least. Orchestration's the biggest slice, 25% — and that's Swarm, not Kubernetes, in case anyone's expecting kubectl questions.

👺

Gizmo: Sounds like a badge nobody's watching too closely anymore. Free credibility, half the effort. 🤑

🐢

Timmy the Turtle: Or a badge nobody's actively selling anymore, Gizmo — which is exactly why you confirm with Mirantis directly before you pay for anything, not assume either way.

🦫

Benny the Beaver: Either way, Swarm's still real infrastructure. Plenty of shops still run it. Worth knowing cold even if the certificate's own status is fuzzy.

✓ Checkpoint

1. Name the six official DCA domains and their weights. 2. What happened in November 2019 that makes DCA's current administering body an open question? 3. Is DCA's Orchestration domain built around Kubernetes or Docker Swarm? 4. What did Universal Control Plane (UCP) and Docker Trusted Registry (DTR) get renamed to after Mirantis's acquisition? 5. What is the single most important thing to confirm before registering for this exam — more important than price or format?

Check your answers
  1. Orchestration 25%; Image Creation, Management & Registry 20%; Installation and Configuration 15%; Networking 15%; Security 15%; Storage and Volumes 10%.
  2. Docker, Inc. sold its Docker Enterprise platform business — Docker Enterprise Engine, UCP, and DTR, along with enterprise customer contracts — to Mirantis, while keeping Docker Desktop, Docker Hub, and Compose for itself. DCA's Swarm-and-enterprise-flavored content lines up with the half that was sold, but no source in this page's research consistently confirmed current DCA ownership beyond "commonly reported to be Mirantis."
  3. Docker Swarm — a different, older, simpler orchestrator than Kubernetes. Someone whose only orchestration experience is kubectl should expect this domain to feel unfamiliar and budget real study time for it.
  4. UCP became Mirantis Kubernetes Engine (MKE); DTR became Mirantis Secure Registry (MSR).
  5. Whether the exam is currently, actively being offered for registration at all — confirm that before checking price, format, or anything else, since this program has already changed administering bodies once.