Practice & Reference · The CNPE Exam

The CNPE Exam — format, registration & a study plan

The Certified Cloud Native Platform Engineer (CNPE) is a hands-on, performance-based exam: no multiple choice, just real tasks on a real cluster with a ticking clock. This page is your logistics briefing — what the exam is, how to register and what it costs, the five domains by weight, the tools you might meet, how CNPE differs from its associate cousin CNPA, a ten-week study plan mapped to this site, and the terminal-speed habits that win points on the day. Treat the numbers here as “true at time of writing” and confirm the live details on the official pages before you pay. For the human side of it — what people who sat the exam say it actually felt like — read the companion page, Field Notes — how people actually passed.

☺ Explain it like I’m 10

Most tests ask you to pick the right answer: A, B, or C. The CNPE is different — it drops you onto a real computer with a real Kubernetes cluster and says, “show me.” Fix the broken thing. Wire up the pipeline. Add the guardrail. A camera watches to make sure it’s really you, and a timer counts down two hours. So you don’t study to recognise answers — you practise until your fingers just do the tasks without thinking.

🦉🐢Your hosts for this topic: Professor Owl & Timmy the Turtle — Owl maps the exam blueprint and plans your weeks, and Timmy brings the calm, methodical checklist that keeps you steady when the clock is running.

What the CNPE actually is

☺ Like you’re 10: It’s a two-hour, “do it for real” test on a live cluster — a proctor watches through your webcam, and you solve tasks instead of answering questions.

The CNPE was launched by the CNCF and The Linux Foundation in late 2025 as the senior, hands-on credential for platform engineers — the person who builds the internal developer platform, not just the person who uses it. It sits above the associate-level CNPA and targets an intermediate-to-senior audience: Principal Platform Engineers, Platform Architects, and SRE/DevOps leads who design golden paths for other teams.

The exam is performance-based and online proctored. You work inside a Linux remote desktop with a terminal and a browser, connected to one or more live Kubernetes clusters, and you complete a series of real tasks — configure GitOps, wire a pipeline, write a CRD, set an alert, apply a policy — that are graded on the resulting cluster state, not on how you got there. There are no multiple-choice questions. A remote proctor supervises through your webcam for the full 120 minutes.

ItemDetail
Full nameCertified Cloud Native Platform Engineer (CNPE)
FormatPerformance-based — solve real tasks on live clusters; no multiple choice
EnvironmentOnline, remote-proctored; a Linux remote desktop (terminal + web UIs) via your browser. Tasks run on designated SSH hosts rather than the base desktop; kubectl (aliased to k), yq, curl, wget and man pages are pre-installed. Proctoring uses streaming audio, video and screen sharing. Component versions (currently Kubernetes v1.35, etcd v3.6) are stated in the official Important Instructions and updated regularly — check the version in force on your exam date.
Duration120 minutes (2 hours)
Number of tasks15–20 performance-based tasks, per the Linux Foundation’s official Important Instructions: CNPE. One candidate (Michał Tomczak) reported 17 tasks in his sitting and several prep sites repeat “17” as if it were fixed — treat it as one data point inside the official range. Plan for up to 20 tasks in 120 minutes.
Passing score64% or above (official CNPE FAQ). Cut scores can be revised over time — check the current FAQ before you sit.
ResultsEmailed within 24 hours of finishing (official FAQ). The Important Instructions page words it as “24 hours from the time that the exam is completed,” so treat 24 hours as the expected turnaround, not a guaranteed maximum.
Domains5 weighted domains (see the bars below)
CostUS$445 — includes one free retake. A bundle with the Full Access Subscription is listed at $625. The Linux Foundation runs frequent promotions and regional pricing, so verify the price at checkout rather than trusting any published figure.
SimulatorTwo killer.sh simulator attempts, each granting 36 hours of access from activation (official FAQ). The product page cites a graded 20-question scenario set modelled on the real exam.
Eligibility window12 months from purchase to schedule and sit the exam — i.e. two attempts within 12 months
Certification validity2 years from the date you pass. To renew you retake and pass before it expires, and the renewal runs 2 years from the new pass date; there is no continuing-education renewal path for CNPE.
PrerequisitesNone formally — you don’t need CKA, CNPA or anything else to register. But CNCF positions CNPE as an advanced credential for experienced platform engineers, senior DevOps/SRE practitioners, architects and infrastructure engineers; CKA-level Kubernetes operational experience is strongly recommended in practice.
Level / audienceIntermediate → senior: Principal Platform Engineer, Platform Architect, SRE/DevOps lead
ProviderCNCF & The Linux Foundation; launched late 2025
⚠ Verify before you pay

Exam price, duration, the domain weights, the tool list, and proctoring rules all change over time. This page reflects the landscape in 2026. Always confirm the current details, the exact allowed-documentation list, and the system-check requirements on the official CNCF and Linux Foundation pages and in the candidate handbook before registering.

Registration & logistics

☺ Like you’re 10: You buy the exam online, you get up to a year to take it, and you need a quiet room, a webcam, and an ID that matches your name.

You register through the Linux Foundation training portal (linked from the CNCF certification page). Payment is $445 and includes one free retake, so a first-attempt miss isn’t the end of the world. When you buy, you also unlock two sessions of the killer.sh simulator — a harder-than-real practice environment you should treat as part of the exam, not an afterthought.

🐢 Timmy’s registration checklist

Walk it in order and nothing surprises you:

  1. Register & pay on the Linux Foundation portal (or grab a THRIVE bundle if you plan to take several certs).
  2. Note your eligibility window — you have 12 months from purchase to schedule and sit the exam. Don’t let it lapse.
  3. Run the system check from the exam dashboard well ahead of the day: supported browser, webcam, microphone, and a stable connection.
  4. Prepare your space — a quiet, private room, a clear desk, and a government-issued photo ID whose name matches your registration exactly.
  5. Schedule your slot, then burn both killer.sh sessions before the real thing so the interface feels familiar.
  6. On the day, join early, complete the proctor’s room and ID scan, and begin.

Three official pages are your source of truth for pricing, policy, and the rules of the room. The third — Important Instructions: CNPE — is the one candidates most often skip, and it’s where the task count, the environment versions, and the allowed-resources rules actually live. Read it end to end the week before you sit:

↗ Register at the Linux Foundation ◆ CNCF certification page ◆ Important Instructions: CNPE

⌁ Note · the certification clock

Two different clocks are easy to confuse. The eligibility window (12 months) is how long you have to take the exam after buying it. The validity (2 years) is how long the certification lasts after you pass — after that you re-certify to stay current.

The five domains & their weights

☺ Like you’re 10: The test spends more time on some jobs than others. GitOps and self-service are each a quarter of the score — so those are where you practise hardest.

The CNPE blueprint splits the platform engineer’s craft into five weighted domains. The bars show how much of the exam each one is worth — your map for where to spend study time. Each links to its lesson on this site:

Half the exam — a full 50% — lives in the two 25% domains, and both are hands-on to the bone: standing up GitOps with Argo CD or Flux and shipping safely with progressive delivery, then exposing CRDs, operators and self-service provisioning. Don’t neglect the smaller domains, though: at 15% each, architecture and security & policy are still worth real points, and their tasks are often quick wins if you’ve practised.

The tools you may see

☺ Like you’re 10: There’s a set of real tools the exam draws from — but you’re not quizzed on trivia. If you meet an unfamiliar one, you’re expected to read its docs and figure it out.

The official curriculum names 15 projects the exam may use. The important caveat, straight from the curriculum: you will not be tested on deep tool-specific knowledge unless it’s referenced in the competencies. You’re a platform engineer, so you’re expected to use the documentation for a tool you don’t know by heart — reading docs fast under time pressure is itself a tested skill. One caution before you lean on that: the CNPE allowlist covers the Kubernetes docs and blog, whatever the task’s Quick Reference box links, and locally installed docs and man pages — not the project websites for Argo CD, Crossplane, Prometheus, OpenTelemetry, Backstage or Helm. See the allowlist note further down. Here they are, grouped by where they tend to appear:

DomainTools you might use
GitOps & Continuous DeliveryArgo (CD / Rollouts / Workflows), Flux, Flagger, Tekton
Platform APIs & Self-ServiceCrossplane (plus the CRD / operator patterns you build by hand)
Observability & OperationsPrometheus, Grafana, OpenTelemetry, Jaeger, OpenCost
Security & PolicyOPA / Gatekeeper, Kyverno, Istio, Linkerd

That’s all fifteen: Argo, Crossplane, Flagger, Flux, Gatekeeper, Grafana, Istio, Jaeger, Kyverno, Linkerd, OPA, OpenCost, OpenTelemetry, Prometheus, and Tekton. For a one-page tour of what each does and the job it maps to, see the tool landscape. The rock-solid foundation under all of them is plain kubectl and the core Kubernetes API — that fluency is assumed, so it’s the one thing worth over-practising.

◆ Key idea

Depth beats breadth in the wrong direction here. You don’t need to memorise every Kyverno flag — you need to be fluent enough in the concepts (admission control, reconciliation, canary analysis) that you can open a tool’s docs and configure it in minutes. Practise the patterns; look up the syntax.

CNPE vs CNPA — which is which

☺ Like you’re 10: CNPA is the “do you know the words?” beginner test. CNPE is the “can you actually build it?” senior test.

The CNCF pairs a foundational associate cert with the professional one. The CNPA (Certified Cloud Native Platform Engineering Associate) is knowledge-based and aimed at people newer to the field; the CNPE is the senior, hands-on credential. CNPA isn’t a prerequisite, but it’s a sensible warm-up — and the concepts overlap heavily with the foundations on this site.

DimensionCNPA (Associate)CNPE (this exam)
LevelFoundational / entryIntermediate → senior / professional
StyleKnowledge-based (multiple-choice-style)Performance-based (solve real tasks)
What it provesYou understand platform-engineering conceptsYou can build and operate a platform on a live cluster
AudienceNewcomers, adjacent roles, studentsPlatform engineers, architects, SRE/DevOps leads
RelationshipThe on-rampThe destination — CNPA is a helpful precursor, not required

A ten-week study plan

☺ Like you’re 10: There’s a full week-by-week plan with labs and checkpoints — it lives on its own page so it has room to breathe.

A good CNPE plan is simple to describe even though it takes weeks to run: weight your study hours by domain percentage — the two 25% domains (GitOps and Platform APIs & Self-Service) get the most time, the two 15% domains get the least — pair every topic with a hands-on lab on a throwaway cluster, and finish by burning both killer.sh sessions plus a full timed mock. Reading about kubectl is not the same as your fingers knowing it, so the plan is built around doing, not reading.

The full ten-week, domain-by-domain plan — with a lesson-and-lab pairing for every week, a resource list, and a readiness checkpoint — lives on its own page: the CNPE study plan.

Exam-day & terminal-speed tips

☺ Like you’re 10: Small habits save minutes: always check which cluster and namespace you’re in, let the computer type the boilerplate for you, and check your work before you move on.

Points are won and lost on speed and precision, not cleverness. These habits are worth drilling until they’re automatic — the goal is that on the day, your hands move while your brain reads the next task.

◆ Context first, every single task

The number-one avoidable mistake is doing perfect work in the wrong cluster or namespace and scoring zero. Each task tells you the context and namespace to use. Before you touch anything, set them — and keep them set:

# 1) Switch to the cluster the task names — do this FIRST, always
kubectl config use-context cluster-name

# 2) Pin the namespace so you stop typing -n everywhere (and stop forgetting it)
kubectl config set-context --current --namespace=team-payments

# 3) A tiny alias kit pays for itself in the first ten minutes
alias k=kubectl
export do='--dry-run=client -o yaml'   # usage: k create deploy web --image=nginx $do > web.yaml
export now='--force --grace-period=0'   # usage: k delete pod broken $now

# 4) Let the cluster generate boilerplate instead of hand-writing YAML
kubectl create deployment web --image=nginx --replicas=3 $do > web.yaml
kubectl create configmap app-cfg --from-literal=LOG=debug $do > cfg.yaml

# 5) When you don't remember a field, ask the API — no docs tab needed
kubectl explain deployment.spec.template.spec.containers.resources

Reach for imperative generators (kubectl create … --dry-run=client -o yaml) to produce a skeleton you then edit, rather than typing manifests from scratch — it’s faster and it won’t fumble indentation. Use kubectl explain to recall a field’s exact path. And know your allowed documentation — the list is narrower than most candidates assume.

⚠ The allowlist is narrower than you think

During the CNPE you may open only: https://kubernetes.io/docs (translations included), https://kubernetes.io/blog/, any task-specific documentation linked in the exam’s Quick Reference box, and locally installed docs (/usr/share, distribution packages, and man pages). You may use those sites’ search, but you must not open external search results or follow outbound links. Critically, docs for Argo CD, Backstage, Crossplane, Prometheus, OpenTelemetry and Helm are not on the CNPE allowlist — even though all of them are in scope for the exam domains. That’s the trap: you must know those tools from memory. (For contrast, CKA/CKAD do allow helm.sh/docs, and CKS allows Falco, etcd, Cilium and Istio docs — CNPE does not inherit those.) Confirm the current list on the official Resources Allowed page before your exam, as it changes.

🦉 Professor Owl’s exam-hall drill · 10 min

Simulate the pressure. Give yourself one task, a 10-minute timer, and these three rules: (1) set context + namespace before anything else; (2) verify your work — after every task, run kubectl get/describe (and hit the endpoint if it’s a workload) to confirm the change is really live; (3) flag and move — if a task fights you for more than its fair share of time, note it, skip it, and come back. Partial progress on ten tasks beats perfection on six. Do this drill daily in your last two weeks.

⚠ Manage the clock, not your ego

Every task carries a weight, usually shown in the interface — spend proportionally. A gnarly 4% task is not worth 25 minutes while three 8% tasks sit untouched. Don’t polish; make it correct, verify it, and move. And don’t leave a task half-applied: a manifest you wrote but never kubectl apply-ed scores nothing.

What test-takers report

☺ Like you’re 10: People who’ve taken it all say roughly the same thing — the clock is the enemy, not the questions. Be quick, don’t get stuck, and finish something on every task.

The following comes from published first-hand accounts by candidates — blog write-ups of their own sittings, not official Linux Foundation guidance. Individual experiences vary and none of it is a promise about your exam form. But the same handful of lessons keeps surfacing, which is usually a sign they’re real:

⌁ Note · one candidate’s numbers aren’t the spec

Where these accounts state hard figures — “I had 17 tasks”, “I finished with 20 minutes spare” — treat them as one person’s exam form, not the blueprint. The official range is 15–20 tasks. Borrow the tactics from first-hand reports; take the numbers from the Linux Foundation.

We’ve collected these accounts, with who said what, on the companion page: Field Notes — how people actually passed.

Your path through this site

☺ Like you’re 10: Every part of the exam has a matching lesson here — read the lesson, do the lab, then test yourself with the quiz and flashcards.

This whole course is built around the exam blueprint, so the mapping is direct. Domain 1 is Platform Architecture & Infrastructure. Domain 2 splits across GitOps Workflows and CI/CD & Progressive Delivery. Domain 3 spans Platform APIs, CRDs & Operators and Self-Service & Portals. Domain 4 is Observability & Operations, and Domain 5 is Security & Policy. Wrap them with the operating-model lessons — anti-patterns and best practices — and the tool landscape.

When you’re ready to test yourself, the Practice & Reference shelf is your revision kit: the printable exam-prep checklist to make sure nothing’s missed, flashcards for quick recall, a self-check quiz, and a searchable glossary for any term that trips you up. Loop: read a lesson, run its lab, then quiz yourself — repeat until the checklist is all ticks.

🎬 At the Platform Guild
🦊

Foxy: Two hours, a live cluster, a camera watching me, and no multiple choice to hide behind. Honestly? I’m terrified.

🦉

Professor Owl: Terror is just unspent preparation. You don’t need to be brilliant — you need to be fast and correct at things you’ve already done twenty times. That’s a plan, not a gamble.

🐢

Timmy: And the plan is boring on purpose. Context first. Verify every task. Flag the hard ones and come back. Slow is smooth, smooth is fast.

👺

Gizmo: Skip the killer.sh sessions — they’re way harder than the real exam, they’ll just crush your confidence. Save your energy! 😈

🐢

Timmy: They’re harder so the real one feels easy, Gizmo. Do both. If you can beat the simulator, exam day is a quiet Tuesday.

🦊

Foxy: …okay. Context first, verify, flag-and-move, both simulators. I can do boring. Boring, I can win.

Nerves are normal — the antidote is reps. Work the ten-week plan, run every lab, and burn both simulator sessions, and you’ll walk in already knowing you can do the work. Now go pick your start point: the foundations if you’re new, or straight into GitOps if the fundamentals are solid. And when you want to hear it from people who’ve already sat in that chair, spend twenty minutes with Field Notes — how people actually passed.

🐢 Timmy’s checkpoint

1. Is the CNPE multiple choice — and how long is it? 2. Which two domains are the heaviest, and what’s each worth? 3. What comes bundled with your registration besides the exam itself? 4. What’s the very first thing you should do at the start of every task? 5. How long is the certification valid, and how long is your window to actually sit the exam? 6. How many tasks will you face, what score do you need, and which documentation sites are you allowed to open?

Check your answers
  1. No — it’s performance-based: you solve real tasks on live clusters in a Linux remote desktop. It runs 120 minutes, online and proctored.
  2. GitOps & Continuous Delivery (25%) and Platform APIs & Self-Service (25%) — together half the exam. Then Observability 20%, and Architecture and Security & Policy at 15% each.
  3. One free retake and two killer.sh simulator sessions (and $445 buys all of it).
  4. Set the context and namespace the task specifieskubectl config use-context … then kubectl config set-context --current --namespace=… — before you change anything, so perfect work never lands in the wrong place.
  5. The certification is valid 2 years after you pass; you have a 12-month eligibility window from purchase to schedule and sit it.
  6. 15–20 tasks (official — not a fixed 17, whatever the prep sites say), and you need 64% or above to pass. Allowed docs are only kubernetes.io/docs, kubernetes.io/blog/, whatever the task’s Quick Reference box links, and locally installed docs and man pages — not Argo CD, Crossplane, Prometheus, OpenTelemetry, Backstage or Helm.