CNPA Mock Exam · Set 4
Sixty more multiple-choice questions, weighted question-for-question to the six domains of the official CNPA curriculum — twenty-two on Core Fundamentals, twelve on observability, security and conformance, ten on continuous delivery, seven on platform APIs and provisioning, five on IDPs and developer experience, four on measuring. About half of this paper is material you will not have met on Set 1, Set 2, Set 3 or the CNPA practice banks; the rest deliberately returns to the same core propositions in new wording. The four papers overlap on purpose, and the overlap sits where the blueprint is heaviest — Core Fundamentals is 36% of the exam, twenty-two questions per paper, eighty-eight across the set, and that topic simply does not hold eighty-eight distinct propositions. Read the four as four sittings rather than four separate question pools. A proposition you recognise from an earlier set is spaced retrieval practice and a measurement of you: answer it instantly and it has stuck; hesitate, and it never really had. This paper has a deliberately different temperament: instead of asking mostly “what is this?”, it puts you in front of a situation and asks what you would do next, or hands you a symptom and asks what is actually going on — plus a run of “which of these is not…” stems, which are the questions candidates most reliably fumble under time pressure. Answer cold, one pass, no notes; every question reveals the answer and the reasoning the moment you commit.
This is practice test number four. The first one mostly asked “do you know what this word means?” This one mostly asks “here’s a mess — what would you do first?” That’s harder, because two of the four answers usually would work; you have to pick the one that works best. When you get one wrong, don’t just read the right answer — say out loud why the one you picked was worse. That sentence is the whole point of doing a fourth paper.
Where Set 4 fits
☺ Like you’re 10: Four practice papers, all built the same way. This is the one you sit last, closest to the real exam.
This site carries four CNPA papers, all weighted identically to the official blueprint and all using the same engine, so a score on one is comparable with a score on another. What differs is the kind of question. Set 1 is the recall paper: definitions, distinctions, the vocabulary you must simply have. Set 4 is the judgement paper: scenarios where several options are defensible and one is clearly better, and negative stems that punish skim-reading. Sit them in that order if you can — recall first, judgement last, as close to your real booking as you can manage.
| Paper | Character | Best sat |
|---|---|---|
| Set 1 | Recall and definitions — the vocabulary of the blueprint | End of your first pass through the six domain pages |
| Sets 2 and 3 | Mixed reinforcement across the same six weights | In between, spaced a few days apart |
| Set 4 (this one) | Diagnosis, best-next-action, and “which is NOT” | The final week, under full exam conditions |
If you have not yet worked through a domain page properly, this is the wrong paper to start with — you will score badly for the wrong reason and learn very little. Start on the CNPA hub, follow the study plan, and read how a CNPA question is built before you sit anything timed. The technique page in particular pays for itself on this paper, because Set 4 is the one where elimination beats recognition.
Sitting it under exam conditions
☺ Like you’re 10: One timer, no other tabs, no looking things up, and an answer for every single question — even the ones you are guessing.
A mock is only worth the conditions you sit it under. Look something up mid-paper and you have measured your search skills, which the real exam will not let you use: the associate-tier papers are closed-book, with no documentation tab and no second screen. So the protocol is deliberately unforgiving — and the discomfort is the product. If you finish Set 4 feeling that it was harder than Set 1, that is not the paper being unfair; it is you meeting the questions that actually separate candidates.
The protocol
- One timer, started once — 120 minutes. You do not pause it for a phone call, a delivery or a question you want to think about later. That is the real allowance: the Linux Foundation’s Multiple Choice Exam FAQ gives multiple-choice candidates 90 minutes with the explicit exception of the CNPA, which is allowed 120. It publishes no question count, so the sixty questions here are a study convention of ours; two hours across them is two full minutes each, so drill at that pace — training at 90 minutes teaches you a rhythm a third faster than the one you will actually be given.
- Leave the domain chips on “All 60”. Filtering by domain is a revision tool for afterwards. Filtering during the sitting turns a mixed paper into six easy little ones, because you stop having to work out which domain a question belongs to — and on the real exam, that switch of context is part of the difficulty.
- Answer every question. Nothing published indicates that Linux Foundation multiple-choice exams deduct marks for a wrong answer — treat that as an assumption to confirm officially rather than a fact you got here — but the advice holds regardless. Eliminate the two you can argue against, pick the better of what remains, move on.
- Commit before you read the explanation. The reveal is instant and it is generous; if you skim it before choosing, you have converted a test into a reading exercise. Choose, then read.
- Write down every question that surprised you — including the ones you got right by luck. Right-for-the-wrong-reason is a gap that will find you again in the exam, where the wording will not match ours.
- Do not immediately re-sit. A second pass an hour later measures short-term memory. Go and read the two weakest domain pages first, then come back and use Shuffle / reset — question order and option order are reshuffled every time, so you cannot pass by remembering that it was the third one.
The time budget
A hundred and twenty minutes across sixty questions is two minutes each, and the failure mode is always the same: three questions eat six minutes apiece, and the last ten get four minutes between them. Give yourself four checkpoints and hold them. If you are behind at a checkpoint, do not try to make it up by rushing — make it up by abandoning: pick the best of what is left on the hard question, mark it in your notes, and move.
| Checkpoint | You should be at | If you are behind |
|---|---|---|
| 30 minutes | Question 15 | You are over-reading the stems. Read the last sentence of the question first — it tells you what is actually being asked. |
| 60 minutes | Question 30 | Cap every remaining question at two minutes by decision, not by hope. |
| 90 minutes | Question 45 | Answer the rest on first instinct plus one elimination pass. First instinct is right far more often than a second-guess. |
| 120 minutes | Question 60, all answered | Nothing blank. A blank is a guaranteed zero; a guess between two options is a coin flip you were offered for free. |
What this paper deliberately is not
It is not a leaked or reconstructed exam — the wording is ours, not the CNCF’s, and the real questions will look and sound different. It is not calibrated to the real exam’s difficulty either, so treat your percentage as a thermometer rather than a verdict. And it is a multiple-choice paper only because the CNPA is a knowledge-based, multiple-choice exam, sitting in the associate tier alongside KCNA, KCSA and CGOA. The performance-based exams — CKA, CKAD, CKS and the CNPE — put you in a live terminal for 120 minutes and grade the resulting cluster state across 15–20 tasks, with a pass mark of 64%. No quantity of multiple choice prepares you for that; for those, the practice that counts is the lab track, the practice-task bank and a timed sitting of CNPE Mock Exam Set 1.
Two of these numbers are published, and this page states them plainly. The Linux Foundation’s Multiple Choice Exam FAQ allows multiple-choice candidates 90 minutes with the exception of the CNPA, whose candidates are allowed 120 minutes, and it sets the pass mark for multiple-choice exams at 75%. Those are the figures used throughout this page. Exam details do still change — duration, question count, pass mark, price, retake terms, eligibility window and certification validity are all revised from time to time — so re-check them at the source before you book rather than trusting any third-party page, this one included. What is additionally safe to state is structural: the CNPA is a CNCF / Linux Foundation associate-level, knowledge-based multiple-choice exam — not a hands-on, performance-based one — delivered online under remote proctoring, with no formal prerequisite, and its blueprint is the six weighted domains below, which sum to 100%. Confirm everything else on the official Linux Foundation CNPA page and the CNCF certification page before you register or pay.
How the sixty questions are weighted
☺ Like you’re 10: The questions are shared out exactly the way the real test shares out its marks. The biggest topic gets the most questions.
The six published weights — 36, 20, 16, 12, 8 and 8 — sum to exactly 100%, and each domain’s share of this paper tracks its weight as closely as sixty whole questions allow. Only rounding differs, and it is worth doing the arithmetic in full: 36% of sixty is 21.6, 20% is 12.0, 16% is 9.6, 12% is 7.2, and each of the two 8% domains is 4.8. Round to the nearest whole question and Core Fundamentals goes up to 22, Continuous Delivery up to 10, Platform APIs down to 7 — but the two 8% domains tie at 4.8 apiece, and no rounding rule can separate them. So the tie is broken by hand: IDPs & DevEx takes 5 and Measuring takes 4, because 22 + 12 + 10 + 7 + 5 + 4 is exactly 60, where giving both of them 5 would be 61 and both of them 4 would be 59. The split is identical to Set 1, which is what makes the two scores comparable — and it means the shape of your result here maps onto the shape of the real exam. Core Fundamentals alone is more than a third of the paper; drop badly there and no amount of tooling detail elsewhere rescues the total.
| Domain | Official weight | Questions here | Where to revise |
|---|---|---|---|
| 🦉 Platform Engineering Core Fundamentals | 36% | 22 | CNPA · Core Fundamentals |
| 🐘 Platform Observability, Security, and Conformance | 20% | 12 | CNPA · Observability, Security & Conformance |
| 🦫 Continuous Delivery & Platform Engineering | 16% | 10 | CNPA · Continuous Delivery |
| 🦋 Platform APIs and Provisioning Infrastructure | 12% | 7 | CNPA · Platform APIs |
| 🦆 IDPs and Developer Experience | 8% | 5 | CNPA · IDPs & DevEx |
| 🐿️ Measuring your Platform | 8% | 4 | CNPA · Measuring your Platform |
| Total | 60 | All six domain pages, in weight order | |
Score your domains, not just your total. A 75% built from “strong everywhere except Core Fundamentals” is far more dangerous than the same 75% built from “solid everywhere, weak on measuring,” because Core Fundamentals carries more than four times the weight of the smallest domain. Fix in weight order, not in the order you happened to find the mistakes.
The character of Set 4
☺ Like you’re 10: Three kinds of tricky question, over and over. Once you can name the kind, it stops being tricky.
Every question on this paper is one of three shapes, and each has a technique that beats it. Learn to spot the shape in the first three seconds and you buy yourself twenty seconds of thinking time on every question — which, across sixty of them, is the entire difference between finishing comfortably and finishing in a panic.
Best-next-action
“Adoption is 20% after a year and teams say it does not do what they need. What should you do first?” Two or three of the four options usually work in some sense; the question is which one you would do first, and why. The technique is to ask what the option actually changes: does it address the cause, or does it manage the symptom more comfortably? On this paper the winning answer is almost always the one that removes the underlying friction, and the most tempting loser is the one that makes the existing painful process faster or more formal — a rota, a review board, a better wiki page, a bigger checklist.
Diagnosis
“Green dashboards, near-zero error rate, one customer whose checkout fails every time.” You are given a symptom and asked what is happening, or where to look. The technique is to ask which of the four explanations is consistent with every detail in the stem — including the detail that seems incidental. If the stem says “nobody has touched Git and nobody ran kubectl,” an answer that requires a human to have acted is already eliminated. Stems on this paper contain no decorative facts.
“Which is NOT”
Negative stems invert the work: three options are true and you are hunting the false one, so the pleasant feeling of recognising a correct statement is now a trap. The technique is mechanical — read the stem twice, write “NOT” at the front of your mind, then test each option with “is this true?” and pick the one that answers no. Under time pressure the classic failure is answering the question you expected rather than the one printed, and it costs marks that you would otherwise have banked.
Before you start the clock, do this once. Take any question below, cover the options, and answer it from memory in a sentence. Then uncover them and find the option closest to your sentence. That is the order the exam rewards — form your own answer, then shop for it — because the alternative is letting four confident-sounding options talk you out of something you actually knew. Do it on three questions, then reset the paper and sit it properly.
The paper — sixty questions
☺ Like you’re 10: Pick an answer. It turns green or red straight away and tells you why yours was wrong too.
Click an option to lock it in — the correct answer is marked, your mistake is marked, and the explanation appears underneath. Each explanation covers both the right answer and the most tempting wrong one, because on a judgement paper the near-miss is the thing worth understanding. The counter and bar at the top track progress and score; the chips filter by domain for revision afterwards; Shuffle / reset reshuffles the questions and the options and starts a fresh attempt. Your best score is remembered in this browser only.
Scoring yourself, honestly
☺ Like you’re 10: Write down your score for each of the six topics, not just one big number.
The counter gives you a percentage. Treat it as a thermometer, not a verdict — this paper is not calibrated to the real exam, and its wording is ours. The real bar is 75%: the Linux Foundation’s Multiple Choice Exam FAQ states that a score of 75% or above must be earned to pass a multiple-choice exam. Aim above it here, because our wording is not theirs and a mock sat comfortably is worth more than one scraped — and re-check the figure at the source before you book, since exam terms are revised over time. What travels most reliably, though, is not the number but the pattern.
| Where you land | What it usually means | The next move |
|---|---|---|
| Under 60% | Foundational gaps rather than exam-technique gaps — and on a judgement paper, usually gaps in why rather than what. | Go back to Core Fundamentals and read it properly, then re-sit that chip alone before touching the rest. |
| 60–75% | You know the material; the edges are fuzzy. Check whether your losses cluster on the “which is NOT” stems — if they do, this is a reading problem, not a knowledge problem. | Re-read your two weakest domain pages, then work the flashcards and the self-check quiz for active recall, and re-read the question-technique page. |
| 75–90% | At or above the official 75% pass mark. What is left is usually one under-read small domain, or a habit of picking the option that manages the symptom. | Spend an afternoon each on IDPs & DevEx and Measuring — 16% of the blueprint between them and the cheapest marks on it. |
| Over 90% | Comfortable. Now guard against recognition rather than knowledge — you have seen four papers on this site. | Do the blank-sheet drill on the hub, then book the exam. If the CNPE is next, start the hands-on lab track — concepts alone will not carry a performance exam. |
One extra check that only a fourth paper can give you: compare your domain percentages with your Set 1 domain percentages. A total that has gone up while one domain has gone down is the most useful signal you will get all week, and it is invisible if you only ever record the headline number.
What to do with the wrong answers
☺ Like you’re 10: Keep a list of what you got wrong and why your answer was wrong. That list is your revision plan.
Whatever you scored, the paper has done its job only if it produces a list. Take every question you got wrong and write, in your own words, why the option you chose was wrong — not why the right one was right. That is a different sentence and a much harder one, and it is the sentence that stops you making the same mistake when the wording changes. Do the same for anything you got right but were not sure about; on a four-option paper, a guess has a 25% chance of hiding a gap from you.
The wrong-answer ledger
Keep it in a file rather than in your head. Five columns, one row per mistake, and it takes about ten minutes after a sitting:
mkdir -p ~/cnpa-revision cat > ~/cnpa-revision/set4-wrong-answers.md <<'EOF' # CNPA Mock Set 4 — wrong answers | Q | Domain | What I picked | Why MY answer was wrong | Page to re-read | |---|--------|---------------|-------------------------|-----------------| | | | | | | EOF open ~/cnpa-revision/set4-wrong-answers.md
After a week of papers, sort the rows by domain. If four of your nine mistakes are in one domain, you have found your afternoon. If they are spread evenly but all share a shape — every “which is NOT” question, say, or every question where you chose the option that added process — you have found something more valuable: a habit, which is cheaper to fix than a syllabus.
Verify the two or three that surprised you
The CNPA is knowledge-based, so you never touch a cluster in the exam — but a concept you have seen happen is one you will never mis-answer again. If the NetworkPolicy question or the Pending-pod question caught you out, spend twenty minutes on a throwaway kind cluster and watch them behave. This paper asks about NetworkPolicy from the L3/L4-versus-L7 angle, but the fastest way to feel what a NetworkPolicy actually is remains the classic self-inflicted outage — default-deny egress with no DNS exception — and it takes two manifests to reproduce:
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: default-deny-egress
namespace: demo
spec:
podSelector: {}
policyTypes:
- Egress
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-dns
namespace: demo
spec:
podSelector: {}
policyTypes:
- Egress
egress:
- to:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: kube-system
podSelector:
matchLabels:
k8s-app: kube-dns
ports:
- protocol: UDP
port: 53
- protocol: TCP
port: 53
Apply the first alone, watch every name lookup in the namespace fail, then apply the second and watch resolution come back. Note that this only demonstrates anything on a CNI that actually enforces NetworkPolicy — the default CNI on kind and minikube historically does not, so start the cluster with Calico or Cilium if nothing happens. And a handful of one-liners cover the other diagnosis questions on this paper:
kubectl describe pod -n demo my-pod
kubectl get events -n demo --sort-by=.lastTimestamp
kubectl auth can-i create deployments --as=system:serviceaccount:ci:builder -n team-a
kubectl get hpa -n demo
kubectl get ingress -n demo -o custom-columns=NAME:.metadata.name,CLASS:.spec.ingressClassName
kubectl get pods -n demo -o jsonpath='{range .items[*]}{.status.containerStatuses[*].imageID}{"\n"}{end}'
That last one is the mutable-tag question made visible: two pods can both say myapp:1.4.2 in their spec and report two different imageID digests, which is exactly how “the same version” behaves differently in two clusters. The wider hands-on kit lives in the lab track, and the command index is on the command reference.
Where each domain is taught
☺ Like you’re 10: Every question here comes from one of six pages. Go back to the page, not to a search engine.
Nothing on this paper is examined that is not taught in the sub-course. The six domain pages are the answer key at exam depth, and the CNPA hub maps each of them to the deeper CNPE lessons on the same ground if you want more than the associate exam asks for.
Core Fundamentals
Declarative resource management, DevOps practices, application environments, platform architecture and capabilities, goals and approaches, CI fundamentals, and continuous delivery and GitOps.
🐘 · 20% · 12 QsObservability, Security & Conformance
Traces, metrics, logs and events; secure service communication; policy engines for governance; Kubernetes security essentials; security in CI/CD pipelines.
🦫 · 16% · 10 QsContinuous Delivery
CI pipelines, the CI/CD relationship, GitOps basics and workflows, GitOps for application environments, and incident response.
🦋 · 12% · 7 QsPlatform APIs
The reconciliation loop, CRDs as self-service APIs, provisioning infrastructure with Kubernetes, and the operator pattern.
🦆 · 8% · 5 QsIDPs & Developer Experience
Simplified access to capabilities, API-driven service catalogs, developer portals, and AI/ML in platform automation.
🐿️ · 8% · 4 QsMeasuring your Platform
Platform efficiency, team productivity, and DORA metrics for platform initiatives.
Around them sits the rest of the CNPA kit: the study plan for pacing, practice questions and technique for the mechanics of a multiple-choice paper, Mock Exam Set 1 for the recall-flavoured sitting, and the shared revision tools — the flashcards, the self-check quiz, the glossary for anything a question assumed you knew, know it cold for the handful of facts that must be automatic, and the exam-prep checklist for the week before the sitting. When you want the wider map of cloud-native credentials, the certifications overview has it.
Dot: Set 1 I got 82%. This one I got 68%. Have I got worse in a week?
Professor Owl: No — you have been asked a different kind of question. Set 1 asked what things are. This one asked what you would do. Those come apart more often than people expect.
Timmy: Where did the fourteen points go, though? Show me the ledger, not the number.
Dot: …six of them were “which is NOT” questions. I read the stem, found a true statement, and clicked it.
Timmy: Then that is not a knowledge gap, it is a reading habit — and it is the cheapest ten marks you will ever recover. Read the stem twice. Every time.
Gizmo: Or just take it four more times. Eventually you memorise which one is green and you get 100%. That counts! 😏
Professor Owl: The options reshuffle on every reset, Gizmo. And the real paper will not use our wording, so a memory of green buttons is worth precisely nothing at 9am on exam day.
Dot: Fine. Ledger, two domain pages, re-sit on Thursday.
Professor Owl: That is the whole method. The paper is just the instrument that produces the list.
Answer these without scrolling up. 1. What is the exact question split across the six domains on this paper, and which two domains together exceed half of it? 2. On a “best next action” question, what usually characterises the most tempting wrong answer? 3. Why does a liveness probe not do the job of a readiness probe? 4. Why can a NetworkPolicy not enforce “service A may not call C’s /admin path”? 5. What breaks first when you apply a default-deny egress policy, and what is the one rule that fixes it? 6. Two clusters run the same image tag and behave differently — what is the mechanism, and what prevents it? 7. How long are you given for the CNPA, what score do you need, and which document publishes both?
Check your answers
- 22 / 12 / 10 / 7 / 5 / 4 — Core Fundamentals, Observability & Security, Continuous Delivery, Platform APIs, IDPs & DevEx, Measuring. Core Fundamentals (36%) and Observability, Security & Conformance (20%) are 56% between them.
- It makes the existing painful process faster, formalised or better documented — a rota, a review step, a longer runbook — instead of removing the friction that caused it.
- Readiness decides whether a pod appears in the Service's endpoints; liveness decides whether it is killed and restarted. Ship only a liveness probe and nothing holds traffic back from a pod that is not ready yet — and if the probe targets something slow to warm up, it restarts the pod before it ever gets there.
- Because a URL path is an HTTP (L7) concept and NetworkPolicy operates at L3/L4 — it can allow or deny the connection, but cannot see which path travels inside it. The mesh’s authorization policy can.
- DNS. Egress to the cluster DNS service is denied along with everything else, so every name lookup fails; the fix is an egress rule permitting UDP and TCP port 53 to kube-dns.
- Tags are mutable pointers — the tag was re-pushed, so the two clusters pulled different digests. Pinning by digest makes the artefact identity immutable.
- 120 minutes and 75%, both published in the Linux Foundation’s Multiple Choice Exam FAQ — which allows 90 minutes for multiple-choice exams generally and names the CNPA as the exception at 120. Price, retake policy, eligibility window and validity are the details to re-check on the official Linux Foundation CNPA page and the CNCF certification page before you register.