OnCallReady

Lesson 19.4 · CKA Exam Drilling · 7 min read

Time: budgets, triage, skipping, partial credit

In plain words

Imagine a treasure hunt with 17 chests hidden in a park and two hours on the clock. Some chests are quick to open and hold a few coins; some take ages and hold a few more. The smart hunter runs around opening all the quick ones first, marks the hard ones on the map, comes back to them later, and spends the last minutes checking every chest was closed properly. The unlucky hunter spends an hour on one stuck lock.

That's CKA time management: about seven minutes per task on average, weights shown on each task, points per minute as the metric, three passes (quick ones, flagged ones, verification), the eight-minute rule for tasks that aren't converging, and partial credit for the parts you can do quickly before skipping.

120 minutes, about 17 tasks

The problem. Candidates who know the material still fail by spending 25 minutes on one stubborn task. A budget per task and a rule for when to skip keep the easy points safe.

What you need to know already: the exam format and weights (19.1, 19.2).

Seven minutes a task on average. Nobody spends seven on each: contexts-into-a-file takes two, an HPA three, a NetworkPolicy eight, a worker upgrade ten or more. The exam is won by spending the time where the points are and not getting stuck.

Weights tell you what a task is worth

Each task shows its weight (e.g. "weight 4%" or "7%"). The long tasks are usually worth more, but not proportionally: an upgrade worth 7% and taking 15 minutes is a worse deal than three 4% tasks taking 3 minutes each. Points per minute is the metric.

tasktypical budgettypical weight
contexts / cert date / join command into files2-3 min2-4%
RBAC role + binding + can-i4-5 min4-6%
expose, HPA, set resources, scale2-4 min2-4%
broken Deployment / Service4-8 min4-8%
NetworkPolicy6-8 min5-7%
PV + PVC + pod6-8 min5-7%
etcd backup (+ restore)5-10 min6-8%
NotReady node / broken control plane6-10 min6-10%
kubeadm upgrade10-15 min7-10%

The drills in this chapter carry exactly these budgets (the header says "budget N min"). Your target is to finish every drill round inside its budget.

The three passes

Pass 1 (about 60-70 minutes). Go through the tasks in order. For each: read it fully, run the context line, and decide in ten seconds whether it is a quick one. Quick ones: do them, verify, move on. Long or unclear ones: flag them (the exam UI has a flag) and skip. A task that needs the cluster fixed first (a broken control plane) is the exception - fix it now, other tasks may depend on it.

Pass 2 (about 40 minutes). The flagged ones, heaviest first.

Pass 3 (whatever is left). Re-read every task's wording against what you did: names, namespace, file paths, exact values, "only", "do not change X". This pass finds more points than any other ten minutes.

The eight-minute rule

When a task has taken its budget and you are not converging (the third wrong guess, the error you do not understand), write down in the exam notepad where you are, flag it, and move on. The next task is worth the same points and you have not lost this one - you come back with fresh eyes in pass 2. The classic failure mode is 25 minutes on one broken node and five unread tasks at the end.

Partial credit is real

A task is several checks. "Create SA, Role, RoleBinding" is probably three or four checks. If you are out of time, the SA and the Role still count. So in pass 1, for a long task you are skipping, it is often worth doing the parts that take 30 seconds (create the namespace-scoped objects, write the file with what you know) before you flag it.

What does NOT earn partial credit: the right objects in the wrong namespace or on the wrong cluster. That is a zero, however good the YAML.

Do not wait for things

Rollouts, pods starting, PVCs binding, nodes going Ready take 10-60 seconds. Do not stare at them:

# an illustration: exam-style task state (the mock tasks build it)
k set image deploy/api api=nginx:1.28 -n shop
deployment.apps/api image updated
k rollout status deploy/api -n shop --timeout=60s
Waiting for deployment "api" rollout to finish: 1 out of 3 new replicas have been updated...

If it is going to take a while, move to the next task and check this one in pass 3. What you must not do is leave a change you never verified, e.g. a Deployment that is actually in ImagePullBackOff because the tag in the task was nginx:1.28 and you typed nginx:1.82.

Where time really goes

From people's post-exam reports and the mock debriefs, the time sinks are always the same:

Mock exams in this chapter

The three mock missions give you 80, 85 and 120 minutes. attempts records your time per attempt. The number to reach before booking: mock 3 under 100 minutes with every objective, twice.

Why it helps

The most common way to fail the CKA with enough knowledge is time: 25 minutes on one broken node and five unread tasks at the end. A clear budget per task shape (contexts two minutes, RBAC five, a NetworkPolicy eight, an upgrade fifteen) and the discipline to flag and move on is worth more than any extra topic you could study in the last week.

The same skill applies on call: timeboxing a hypothesis, writing down where you are, handing over or switching approach instead of tunnelling. Knowing not to stare at rollouts, and to start slow operations early and check them later, is how you run parallel work during an incident too. The third pass, re-reading every task against what you did, finds more points than any other ten minutes.

FAQ

Should I do the tasks in order?

Read them in order, but don't do them all in order. In the first pass, decide in about ten seconds whether a task is quick: do the quick ones, flag the long or unclear ones. The exception is a task that breaks the cluster for others (a broken control plane): fix that now, since other tasks may depend on it. Then do flagged ones, heaviest first.

What's the eight-minute rule?

When a task has used its budget and you're not converging (the third wrong guess, an error you don't understand), write down where you are in the exam notepad, flag it and move on. You haven't lost it; you come back in pass two with fresh eyes. Sinking 25 minutes into one task is the classic way to fail with enough knowledge.

How does partial credit change what I do?

For a long task you're about to skip, spend 30 seconds on the easy parts first: create the ServiceAccount and Role even if the binding needs thought, write the answer file with what you know. Each check is scored separately. But nothing done in the wrong namespace or on the wrong cluster counts, however good it is.

Should I wait for a rollout to finish before the next task?

No. Start it, glance at rollout status --timeout=60s if it's quick, and otherwise move on and check it in the verification pass. What you must not do is never check: a typo in an image tag means a Deployment stuck in ImagePullBackOff, and the graded state is whatever is left at the end.

Where does time really go on the exam?

Typing names instead of copying them, YAML indentation (tabs, auto-indent when pasting), browsing the docs instead of searching, reading all of a describe output instead of the last Events and Last State, waiting for things, and debugging your own typos. k get before k describe: a NotFound in one second beats reading the describe of the wrong object.

In an interview Junior

How do you prioritise when you have more tasks than time?

By points per minute, in passes:

  1. First pass: read each task, run its context line, decide in seconds. Quick ones (contexts into a file, an HPA, an RBAC role) - do them, verify, move on. Long or unclear ones - flag and skip. Exception: if the cluster itself is broken, fix it now, other tasks depend on it.
  2. Second pass: the flagged ones, heaviest first.
  3. Third pass: re-read every task against what you did - names, namespace, paths, "only", "exactly". This finds more points than any other ten minutes.

And two rules: the eight-minute rule - when a task has used its budget and you are not converging, note where you are, flag it, move on; and partial credit - before skipping a long task, do the 30-second parts. Do not stare at rollouts; check them later. In practice, attempts records your time per drill against its budget.

The same applies outside exams: in an incident, timebox a hypothesis instead of spending 30 minutes on one.

Also asked: During an incident you have spent 30 minutes on one hypothesis without progress. What do you do? · How do you estimate time for operational work like an upgrade? · Why is partial work on a task better than none?

Practise this lesson in the terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.