Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
What is the relationship between topics and partitions? (Choose two.)
Kafka topics are split into one or more partitions to enable parallelism and scalability.
Each partition belongs to exactly one topic; it cannot span multiple topics.
Why does Kafka use ZooKeeper? (Choose two.)
ZooKeeper stores metadata such as partition leadership and ISR (in-sync replicas), which brokers use to coordinate.
Kafka uses ZooKeeper to perform leader election for the Controller broker, which manages cluster metadata and leadership changes.
You are managing a cluster with a large number of topics, and each topic has a lot of partitions. A team wants to significantly increase the number of partitions for some topics.
Which parameters should you check before increasing the partitions?
Each Kafka partition maps to multiple log segment files, and each segment results in open file descriptors on the broker. When the number of partitions increases significantly, it can exceed the OS-level limit for open files per broker process, leading to failures or degraded performance. Therefore, it is essential to check and possibly increase the ulimit -n (max open files) setting on the broker machines.
How does Kafka guarantee message integrity after a message is written on a disk?
Kafka ensures message immutability for data integrity. Once a message is written to a Kafka topic and persisted to disk, it cannot be modified. This immutability guarantees that consumers always receive the original message content, which is critical for auditability, fault tolerance, and data reliability.
By default, what do Kafka broker network connections have?
By default, Kafka brokers use the PLAINTEXT protocol for network communication. This means:
No encryption -- data is sent in plain text.
No authentication -- any client can connect without verifying identity.
No authorization -- there are no access control checks by default.
Security features like TLS, SASL, and ACLs must be explicitly configured.
Where are Apache Kafka Access Control Lists stored'?
In Apache Kafka (open-source), Access Control Lists (ACLs) are stored in ZooKeeper. Kafka brokers retrieve and enforce ACLs from ZooKeeper at runtime.
Exam domains verified against: Official Confluent CCAAK exam guide, last checked September 2026.
Covers core Kafka architecture including brokers, topics, partitions, and how data flows through clusters. Tests understanding of consumer groups and the fundamental concepts a Kafka administrator needs to manage production systems.
Focuses on securing Kafka environments through authentication mechanisms and authorization policies. Includes configuring encryption for data in transit and at rest to protect sensitive information.
Addresses different Kafka deployment topologies and architectural patterns. Covers decisions about cluster sizing, replication strategies, and infrastructure planning for production deployments.
Examines use and management of Kafka Connect for data integration with external systems. Tests knowledge of connectors, configuration, and managing data flows into and out of Kafka clusters.
The largest section covering configuring broker properties and tuning performance settings. Includes managing topic-level settings and applying best practices for production-grade environments.
Sample question from this domain above: Q3
Focuses on monitoring Kafka clusters and understanding metrics that indicate cluster health. Tests ability to track performance, identify bottlenecks, and maintain visibility into production systems.
Tests diagnostic skills for identifying and resolving common issues in Kafka clusters. Covers analyzing logs, understanding error conditions, and applying systematic approaches to resolve problems.
Describe the logging capabilities of SR Linux and SR Linux log files; Describe the purpose and operation of interface ACLs; Describe the purpose and operations of system ACLs; Describe the purpose and operation of the CPM-filter and its policers; Configure CPM-filter and interface ACLs; Describe the capture-filter and how it can be used for traffic monitoring
Describe the different types of SR Linux users and how privileges are managed through user roles; Explain why TLS server profiles may be required and how to configure a TLS profile for gNMI or JSON-RPC; List the requirements for zero-touch provisioning (ZTP); Describe the configuration and autoboot process with ZTP; Describe common ZTP failure scenarios
Common questions about the exam itself