CNPA Mock Exam · Set 3
A third complete paper for the Cloud Native Platform Engineering Associate: sixty multiple-choice questions, split question-for-question by the six official domain weights — twenty-two on Core Fundamentals, twelve on observability, security and conformance, ten on continuous delivery, seven on platform APIs and provisioning, five on IDPs and developer experience, four on measuring. About half of this paper is material you will not have met in Set 1, Set 2, Set 4 or the practice banks; the other half deliberately comes back to the same core propositions in different words. The papers are not disjoint pools and were never going to be — Core Fundamentals alone is 36% of the blueprint, so four papers need eighty-eight questions from one associate-level topic, and “what a platform is, declarative versus imperative, golden paths, reconciliation” does not contain eighty-eight distinct propositions. The overlap is therefore concentrated exactly where the exam puts its marks, which is where you want it. Sit the four as four sittings days apart, not as one long unique-item pool: meeting a proposition you have already answered is spaced retrieval, and it reports on you — instant means consolidated, hesitant means it was never as solid as your first score suggested. What makes this set different is its shape: almost every question puts two things side by side that candidates routinely mix up — golden path and guardrail, prune and self-heal, RED and USE, authorisation and admission, DORA and SPACE — and asks you to say which is which. If you have been passing papers by recognising vocabulary, this is the one that finds out.
You know how “sea lion” and “seal” sound almost the same, and you can nod along for years without ever being able to tell them apart? Most exam mistakes are like that. You almost know the thing — you just get it confused with its neighbour. This test is sixty pairs of neighbours. Pick an answer even when you are only half sure, because the moment you commit, it tells you which one you actually had backwards. That is the whole point.
How to sit Set 3
☺ Like you’re 10: One sitting, no notes, no other tabs, and an answer for every single question even when you are guessing.
A mock is only worth something if it measures what you can retrieve unaided. The moment you open the glossary mid-paper you stop testing recall and start testing search skill, and search is exactly the thing you will not have in a remote-proctored associate exam. So sit this the way you will sit the real one: one uninterrupted block, no documentation, no second monitor, no “I will just check that one.” The wider sitting technique — the room, the ID, the system check, the day before — lives in the exam guide and the exam-prep checklist; this page is only about the paper.
The protocol
- Set a clock for 120 minutes. That is the CNPA’s published allowance: the Linux Foundation’s Multiple Choice Exam FAQ gives candidates 90 minutes for its multiple-choice exams with the exception of the CNPA, which gets 120. Two minutes a question, with a little slack for the long ones.
- Leave the domain chips on “All” for the first pass. Filtering by domain is a revision tool, and using it on a first sitting quietly tells you the answer’s category before you have read the options.
- Answer every question. Nothing published indicates that Linux Foundation multiple-choice exams penalise a wrong answer — treat that as an assumption to confirm officially rather than a fact you got here — but the advice survives either way: eliminate two, then pick the better of the remaining two. A blank is a guaranteed zero.
- Read the explanation immediately, then move on. Do not stop to research. If the explanation surprised you, write the topic on your miss log and keep going.
- Do not re-sit today. A second attempt an hour later measures short-term memory. Read your two weakest domain pages first, sleep on it, and come back with Shuffle / reset — the question order and the option order are reshuffled every time, so “it was the second one” gets you nothing.
Where this set sits among the papers
These CNPA papers are designed to be sat in sequence rather than raced through in an afternoon. Set 1 is the broad diagnostic — take it first, cold, to find out which domains are thin. Set 3 is the one to take once you believe you have fixed them, because it will not accept a fuzzy answer: a question that asks whether prune or self-heal deletes things is either right or wrong, with no partial credit for a general feeling about GitOps. If you want targeted drilling between papers rather than another full sitting, the practice-question guide explains how CNPA items are constructed and how to work a bank so it teaches instead of merely scoring, and the study plan tells you where in the four weeks each paper belongs.
What this paper deliberately is not
It is not a leaked, reconstructed or officially sanctioned exam, and every word of it is ours rather than the CNCF’s. Three honest caveats follow from that. First, the real exam’s question count and difficulty are set by the Linux Foundation and may not resemble the sixty questions here; the clock, at least, is not in doubt — the Linux Foundation allows CNPA candidates 120 minutes, which is what this paper is timed to. Second, a multiple-choice paper can only test what can be phrased as an option list; the CNPA also rewards being able to explain an idea in a sentence, which is why Master Panda’s blank-sheet drill belongs in your plan alongside these papers. Third — and this is the one people get backwards — this format is right only because the CNPA is knowledge-based. It sits in the associate, multiple-choice tier next to KCNA, KCSA and CGOA. The performance-based exams — CKA, CKAD, CKS and the CNPE — drop you into a live terminal and grade the resulting cluster state, and no quantity of multiple choice prepares you for that. For those, the practice that counts is the lab track, the practice-task bank and a timed sitting of CNPE Mock Exam Set 1. The certifications overview maps the whole tier structure.
Duration, question count, pass mark, price, retake terms, eligibility window and certification validity are all revised over time, so re-check them on the official pages before you book — that is a habit, not a hedge. Two of them the Linux Foundation does publish, and this page states them plainly: the Multiple Choice Exam FAQ allows CNPA candidates 120 minutes — 90 minutes is the figure for its other multiple-choice exams, and the CNPA is the named exception to it — and requires 75% or above to pass. What is safe to state beyond that is structural: the CNPA is a CNCF/Linux Foundation associate-level, knowledge-based multiple-choice exam — not a hands-on, performance-based one like CKA, CKS or the CNPE — delivered online under remote proctoring, with no formal prerequisite, and its blueprint is the six weighted domains below, which sum to 100% and are reproduced from the official CNCF curriculum. Confirm everything else on the official Linux Foundation CNPA page and the CNCF certification page before you register or pay.
Your time budget on sixty questions
☺ Like you’re 10: Give each question about two minutes. If one is fighting you, guess, mark it, and come back — do not let it eat three others.
A hundred and twenty minutes across sixty questions is two minutes each, and that average is far more generous than it sounds, because a knowledge-based paper is bimodal: perhaps forty questions you either know or do not know within fifteen seconds, and twenty that genuinely need thinking. The forty fast ones buy the twenty slow ones their time. What ruins a sitting is not slow reading — it is a single question you refuse to leave.
The three-pass shape
Work it in three passes rather than one. Pass one, roughly 60 minutes: answer everything you are confident about and skip nothing — commit a best guess even on the hard ones, because an answer you can revisit is worth more than a blank you might not get back to. Pass two, roughly 40 minutes: return to the ones you flagged, and this time use elimination deliberately rather than intuition. Pass three, the last 20 minutes: re-read only the questions where you changed your mind, and change nothing else. Reviewing every answer from the top is how confident papers turn into mediocre ones.
How to attack a distinction question specifically
This set is built from pairs, so it rewards a specific technique. Before you read the four options, say to yourself what each of the two named things is. “Prune deletes what Git no longer has; self-heal reverts what the cluster changed.” “A quota caps the namespace total; a LimitRange sets per-object defaults and bounds.” Now read the options. Roughly half of the wrong answers in any distinction question are simply the correct pair inverted, and once you have stated both sides in your own words, the inversion is glaringly obvious instead of subtly plausible. If you cannot state both sides, that is your answer about what to revise, regardless of which option you end up picking.
The single most common wrong answer on a distinction question is the correct pair with the two halves swapped. It reads fluently, it uses all the right vocabulary, and it is exactly wrong. Defend against it by defining both terms before you look at the options — never after.
How the sixty questions are weighted
☺ Like you’re 10: The questions are shared out the same way the real test shares out its marks — the biggest topic gets the most questions.
The six published weights — 36, 20, 16, 12, 8 and 8 — sum to exactly 100%, and each domain’s share of this paper tracks its weight as closely as sixty whole questions allow. Only rounding differs. Sixty questions against the six weights gives 36% → 21.6, 20% → 12.0, 16% → 9.6, 12% → 7.2, 8% → 4.8 and 8% → 4.8. Core Fundamentals and Continuous Delivery round up to 22 and 10, Platform APIs rounds down to 7, and Observability is exact at 12 — but the two 8% domains are identical at 4.8 apiece, and the other four already account for 51 questions, so rounding both the same way gives 59 or 61 rather than 60. So the tie is broken by hand: IDPs & DevEx takes five and Measuring takes four. Nothing in the blueprint distinguishes them; one of the two simply has to carry the last question so the paper totals exactly sixty. That gives the split 22 · 12 · 10 · 7 · 5 · 4, identical to Set 1, so the two papers are directly comparable domain by domain. Core Fundamentals alone is more than a third of the mark; drop it badly and no amount of tooling detail elsewhere rescues the score.
| Domain | Official weight | Questions here | Where to revise |
|---|---|---|---|
| 🦉 Platform Engineering Core Fundamentals | 36% | 22 | CNPA · Core Fundamentals |
| 🐘 Platform Observability, Security, and Conformance | 20% | 12 | CNPA · Observability, Security & Conformance |
| 🦫 Continuous Delivery & Platform Engineering | 16% | 10 | CNPA · Continuous Delivery |
| 🦋 Platform APIs and Provisioning Infrastructure | 12% | 7 | CNPA · Platform APIs |
| 🦆 IDPs and Developer Experience | 8% | 5 | CNPA · IDPs & DevEx |
| 🐿️ Measuring your Platform | 8% | 4 | CNPA · Measuring your Platform |
Two consequences worth holding on to. First, the two largest domains are 56% of the paper between them — thirty-four of these sixty questions — so a weak Core Fundamentals score cannot be offset by a perfect Measuring score, which is worth four marks in total. Second, the three smallest domains total 28%, which is more than a quarter of the exam, and they are the ones candidates skim because they feel soft. Catalogs, portals, inner loops, unit cost and DORA definitions are all crisply testable, and an afternoon each is the highest return per hour anywhere on this blueprint.
This set’s character — questions that test a distinction
☺ Like you’re 10: Nearly every question here is “these two things look alike — which is which?”
The CNPA is not a trivia exam, and its harder items are rarely about obscure facts. They are about boundaries: two adjacent concepts, one question, and four options of which three are near-misses. A candidate who has read widely but never articulated the boundary will find all four options plausible, which feels like bad luck and is in fact a precise diagnosis. Set 3 is built almost entirely from those boundaries, so it fails you fast and specifically rather than slowly and vaguely.
The pairs this paper leans on
A partial map, so you can see what is coming and pre-load the distinctions:
| Domain | Pairs you will be asked to separate |
|---|---|
| 🦉 Core Fundamentals | Golden path vs guardrail · gate vs guardrail · Helm vs Kustomize · ResourceQuota vs LimitRange · ConfigMap vs Secret · tag vs digest · deployment vs release · day 1 vs day 2 · SLI vs SLO vs SLA · DevOps vs platform engineering |
| 🐘 Observability & Security | Monitoring vs observability · Events vs audit log · mutating vs validating admission · head- vs tail-based sampling · RED vs USE · authn vs authz vs admission · Role vs ClusterRole · Sealed Secrets vs External Secrets · fail-open vs fail-closed admission · scanning vs runtime detection |
| 🦫 Continuous Delivery | Blue/green vs rolling · Argo CD vs Flux · prune vs self-heal · webhook vs interval · progressive delivery vs continuous deployment · MTTD vs MTTA vs MTTR · fields Git owns vs fields another controller owns |
| 🦋 Platform APIs | Crossplane vs Terraform · owner references vs finalizers · deprecated vs removed API versions · conditions vs a phase field · schema validation vs policy · webhook vs controller |
| 🦆 IDPs & DevEx | Catalog vs scaffolder · scorecard vs admission policy · portal vs API vs CLI · inner loop vs outer loop |
| 🐿️ Measuring | DORA vs SPACE · change failure rate vs a raw defect count · adoption vs satisfaction · total spend vs unit cost |
Reading that table is not cheating, and it will not save you — knowing that a question is about prune versus self-heal is a long way from being able to say which deletes and which reverts. Use it afterwards instead: any row you cannot narrate confidently is a revision target, whatever you scored.
The paper — sixty questions
☺ Like you’re 10: Pick an answer. It turns green or red straight away and tells you why yours was wrong as well as why the right one is right.
Click an option to lock it in — the correct answer is marked, your mistake is marked, and the explanation appears underneath. Every explanation does two jobs: it justifies the correct option, and it names the most tempting wrong one and says why it fails. The counter and bar track how far through you are and how many you have right; the chips filter by domain; Shuffle / reset reshuffles both the questions and their options and starts a clean attempt. Your best full-paper percentage on this set is remembered in this browser only, under a storage key unique to Set 3, so Set 1’s result and this one never overwrite each other.
Scoring yourself against the associate bar
☺ Like you’re 10: The number matters less than which questions you lost. Losing four in the small domain is nothing; losing nine in the big one is everything.
The counter gives you a percentage, and the bar it is aiming at is a real one: the Linux Foundation’s Multiple Choice Exam FAQ states that a score of 75% or above is required to pass, which on a sixty-question paper is forty-five right. Treat your number here as a thermometer rather than a verdict all the same: this paper is not calibrated to the real exam’s difficulty in either direction, so scoring 78% here is not a prediction that you will score 78% there. What travels reliably is the pattern of your misses, not the total. (Cut scores are revised from time to time like everything else — glance at the official page when you book.)
Weight your score before you read it
Score the domains, not just the total. Because Core Fundamentals is 36% of the blueprint, a mark lost there is worth roughly four and a half marks lost in Measuring. Two candidates can both finish on 75% and be in completely different positions: one is solid everywhere and thin on measuring, which is a week of light reading; the other is strong on tooling and shaky on fundamentals, which is a genuine re-study. Work out your percentage per chip — the filter makes that easy — and fix in weight order rather than in the order you found the mistakes.
| Where you land | What it usually means | The next move |
|---|---|---|
| Under 60% | Foundational gaps, not exam-technique gaps. Distinction questions expose these first, because you cannot separate two ideas you have not properly learned individually. | Go back to Core Fundamentals and read it end to end, then re-sit that chip alone before touching the rest. |
| 60–75% | You know the material and the edges are fuzzy — which is exactly what this set is designed to detect. Check whether your losses cluster on inverted-pair options. | Re-read your two weakest domain pages, then work the flashcards and the self-check quiz for active recall, and re-sit chip by chip. |
| 75–90% | On track. What remains is usually one under-read small domain plus a handful of genuine confusions. | Spend an afternoon each on IDPs & DevEx and Measuring, then narrate every row of the pairs table above from memory. |
| Over 90% | Comfortable — but guard against recognition. You have now seen these options; a second attempt proves less than the first did. | Do the blank-sheet drill on the CNPA hub, confirm the official logistics, and book it. If the CNPE is next, start the hands-on lab track — concepts alone will not carry a performance exam. |
The CNPE is the performance-based professional exam — 120 minutes, roughly 15–20 hands-on tasks, and 64% to pass. The CNPA is the knowledge-based associate exam, and it also runs to 120 minutes — a coincidence of clocks, nothing more — but it is multiple choice and its bar is 75%, per the Multiple Choice Exam FAQ. Same duration, entirely different paper and a cut score eleven points higher. If you catch yourself revising the CNPA against 64%, you are studying the wrong blueprint — see the CNPE exam guide.
What to do with your wrong answers
☺ Like you’re 10: For every one you got wrong, write down why your answer was wrong — not why the right one was right.
This is the part almost everyone skips, and it is the part that moves your score. Reading the correct answer produces a warm feeling of recognition and almost no durable memory. Writing one sentence explaining why the option you chose is wrong forces you to locate the actual misconception, and on a distinction paper that sentence is usually short and brutal: “I had prune and self-heal the wrong way round.” You cannot un-learn that once you have written it down.
The miss log
Keep it in a plain file so it survives the browser session. One entry per wrong answer, three lines each, and a link back to the page that teaches it:
mkdir -p ~/cnpa-prep cat >> ~/cnpa-prep/miss-log.md <<'EOF' ## Set 3 - attempt 1 - topic: prune vs self-heal (domain: Continuous Delivery) I chose: "they are the same drift-correction behaviour" Why mine was wrong: prune acts on DELETIONS in Git; self-heal acts on CHANGES made in the cluster. Two directions, two switches. Revise: cnpa-continuous-delivery.html EOF
Re-read the log — not the paper — before your next sitting. Ten minutes with your own sentences beats an hour re-reading prose you already agreed with.
Sort your misses into four buckets
Not every wrong answer means the same thing, and treating them identically wastes revision time. Sort each one: (1) never knew it — go and read the domain page, this is real study; (2) knew it but had the pair inverted — the characteristic Set 3 failure, fixed by narrating both sides aloud until it is boring, not by re-reading; (3) misread the question — an exam-technique problem, fixed by slowing down on pass one, and worth counting because a paper full of these is a paper you can rescue in an afternoon; (4) guessed and got lucky — these are wrong answers wearing a green tick, so mark them as misses and revise them anyway. The practice-question guide expands this bucket drill and the elimination technique behind it.
Space the re-sit, and reset the saved score
Leave at least two days, ideally a week, before you take Set 3 again — spacing is what converts a correction into a memory, and an immediate retake mostly measures how well you remember being told. When you do come back, the paper reshuffles itself, so the order gives you nothing. If you want a genuinely clean slate including the remembered best percentage, clear the storage key from your browser console:
localStorage.removeItem("lpe.cnpa.mock3.best.v1");Where each domain is taught
☺ Like you’re 10: Every question here comes from one of six pages. Go back to the page, not to a search engine.
Nothing in this paper is examined that is not taught in the sub-course, so the six domain pages are the direct answer key at exam depth. The CNPA hub maps each of them to the deeper CNPE lessons on the same ground if you want more than the associate exam asks for, and the study plan sequences them across four weeks.
Core Fundamentals
Declarative resource management, DevOps practices, application environments, platform architecture and capabilities, goals and approaches, CI fundamentals, and continuous delivery and GitOps.
🐘 · 20% · 12 QObservability, Security & Conformance
Traces, metrics, logs and events; secure service communication; policy engines for governance; Kubernetes security essentials; security in CI/CD pipelines.
🦫 · 16% · 10 QContinuous Delivery
CI pipelines, the CI/CD relationship, GitOps basics and workflows, GitOps for application environments, and incident response.
🦋 · 12% · 7 QPlatform APIs
The reconciliation loop, CRDs as self-service APIs, provisioning infrastructure with Kubernetes, and the operator pattern.
🦆 · 8% · 5 QIDPs & Developer Experience
Simplified access to capabilities, API-driven service catalogs, developer portals, and AI/ML in platform automation.
🐿️ · 8% · 4 QMeasuring your Platform
Platform efficiency, team productivity, and DORA metrics for platform initiatives.
Around the sub-course, the shared revision kit still applies: Mock Exam Set 1 for a second full paper, the practice-question guide for how items are built and how to eliminate, the self-check quiz for mixed recall, the flashcards for vocabulary, the glossary for anything a question assumed you knew, know it cold for the handful of facts that must be automatic, the exam-prep checklist for the week before the sitting, and the certifications overview when you want to know what to take next.
Foxy: Seventy-eight percent. But it felt worse than Set 1, and I scored higher on Set 1.
Remy: Because this one asks you to separate things, and separating is harder than recognising. Feeling worse at a higher score is usually a good sign.
Professor Owl: Show me the thirteen you lost. …Ah. Nine of them are the correct pair with the halves swapped. That is one afternoon of work, not one week.
Foxy: How do I fix “swapped”? I already read the pages.
Professor Owl: Reading is the problem. Say both halves out loud — “prune deletes what Git dropped, self-heal reverts what the cluster changed” — until it bores you. Boredom is the finish line.
Gizmo: Or take it six more times. By attempt four you’ll know which option is green without reading it. Score of 100%! 😏
Remy: Which is why the options reshuffle, Gizmo. And the real exam’s wording will not match ours anyway — you would be memorising a paper nobody is going to set you.
Timmy: The version of this that actually matters is at 2am, when someone asks whether the policy that just blocked a deploy was a guardrail or a gate. Sixty seconds of exam trivia; ten years of career.
Answer these without scrolling up, and give both halves of every pair. 1. Which two CNPA domains make up 56% of the paper, and what are their weights? 2. Prune and self-heal — which one acts on a deletion in Git, and which on a change in the cluster? 3. What does a ResourceQuota cap that a LimitRange does not? 4. In what order does the API server run authentication, authorisation and admission — and which of the three can inspect the object’s contents? 5. RED and USE: which applies to a request-driven service, and which to a disk? 6. Lead time for changes starts at which event, and ends at which? 7. Which is the guardrail and which is the gate: an admission policy evaluated on every apply, or a weekly change-approval meeting? 8. How long do you get for the CNPA, what score does it take to pass, and which exam facts are not published and must be confirmed officially?
Check your answers
- Core Fundamentals (36%) and Observability, Security & Conformance (20%) — thirty-four of these sixty questions between them.
- Prune deletes live resources whose manifests were removed from Git; self-heal reverts out-of-band changes made in the cluster back to what Git says.
- A ResourceQuota caps the aggregate resources a namespace may consume; a LimitRange sets default, minimum and maximum values for individual objects in it.
- Authentication → authorisation → admission → persistence. Only admission inspects the object itself; RBAC decides whether the identity may perform the verb on the kind, and knows nothing about the pod’s contents.
- RED (rate, errors, duration) for request-driven services; USE (utilisation, saturation, errors) for resources such as disks, CPUs and queues.
- It starts at code committed and ends when that code is running successfully in production — not idea-to-release, which is product lead time.
- The admission policy is the guardrail — automatic, consistent, applied to every change including the urgent one. The weekly meeting is the gate — periodic, human, queue-forming.
- 120 minutes and 75% to pass — both published in the Linux Foundation’s Multiple Choice Exam FAQ, where the CNPA is the named exception to the 90 minutes allowed for other multiple-choice exams. What is not published, and must come from the official Linux Foundation CNPA page and the CNCF certification page: question count, price, retake terms, eligibility window and validity — and re-check the two above while you are there, because these things do get revised.