
Kyverno Certified Associate (KCA) Practise Exam
-
Questions
60
- Question bank 290
- Updated 25 Sep 2026
-
Time limit
90 min
-
Pass grade
75%
- Version 2026
Pay once per exam. No subscription. Trial (1,00 $) is deducted from full access if you upgrade.
- Unlimited attempts
- Explanations
- Practice
- More questions across retakes
- Review questions
- History
- Unseen first
- Weak domains
- 1 timed attempt
- Score only
Who it is for
- Platform, DevOps, and DevSecOps engineers preparing for the Kyverno Certified Associate exam.
- Kubernetes practitioners who need hands-on practice with Kyverno policy-as-code, admission control, and operations.
What this exam covers
- Fundamentals of Kyverno — 18%
- Installation, Configuration, and Upgrades — 18%
- Kyverno CLI — 12%
- Applying Policies — 10%
- Writing Policies — 32%
- Policy Management — 10%
What you will practice
- Install, configure, and upgrade Kyverno with Helm or release YAML, including HA replicas, resourceFilters, and controller RBAC.
- Select resources with match/exclude and preconditions, then write validate, mutate, generate, cleanup, and verifyImages rules.
- Test policies shift-left with kyverno apply, kyverno test, and kyverno jp before they reach a cluster.
- Read PolicyReports, scope PolicyExceptions, and interpret Kyverno Prometheus metrics.
About this practice exam
The Kyverno Certified Associate (KCA) exam demonstrates a solid understanding of Kyverno as a Kubernetes policy engine: YAML and CEL policies, admission control, and policy-as-code workflows.
The KCA is a pre-professional certification for Kubernetes administrators, DevOps and DevSecOps engineers, security analysts, cloud-native developers, and compliance professionals. It validates that you can install and upgrade Kyverno, apply and write policies, use the CLI, and manage reports, exceptions, and metrics.
The official exam is online, proctored, and multiple-choice. This practice exam follows the current Linux Foundation domain weights so you can drill the same areas the live blueprint emphasizes.
The KCA validates understanding of:
- Kyverno fundamentals: Policy versus ClusterPolicy, one action per rule (validate, mutate, generate, or verifyImages), admission webhooks, YAML manifests, and OCI image or artifact verification.
- Installing Kyverno in a dedicated namespace with Helm (recommended) or tagged YAML, controller flags and ConfigMap filters, RBAC, high availability, certificates, and upgrades.
- The Kyverno CLI: installing the binary or krew plugin, kyverno apply dry-runs, kyverno test expected-result suites, and kyverno jp for JMESPath.
- Applying policies: match and exclude with any/all, resource selection (kinds, names, namespaces, subjects, roles), common settings such as operations and background, and preconditions.
- Writing policies: validation (pattern, deny, anchors, foreach, podSecurity, CEL), mutation and JSON Patch, autogen, generate (clone/data, synchronize), cleanup or DeletingPolicy, verifyImages (Cosign and Notary), variables, and API or GlobalContext data.
- Policy management: PolicyReports in the open report format, PolicyExceptions, and Prometheus metrics on the Kyverno metrics Services.
Only logged in customers who have purchased this product may leave a review.

Reviews
There are no reviews yet.