Kubernetes and Cloud Native Associate (KCNA) practice questions
230 free questions with answers and explanations.
- 151.A client is running a mission-critical financial application on Kubernetes. They require an observability strategy that ensures an immediate response to any deviation from normal behavior, even subtle ones, to prevent service disruptions. This necessitates defining clear thresholds for key metrics and automatically notifying responsible teams when these thresholds are breached. Which observability practice is being described?Cloud Native Observability
- 152.A system administrator observes that their Kubernetes cluster's CPU utilization frequently spikes unexpectedly, but they lack historical context to understand the pattern or root cause. Which component of the Prometheus ecosystem would best help them visualize this historical data and identify trends?Cloud Native Observability
- 153.A security operations center (SOC) team needs to audit all administrative actions performed within their Kubernetes cluster, including who made changes, when, and from where. This data is critical for compliance and forensic analysis. Which specific type of log within Kubernetes provides this granular information about API server requests?Cloud Native Observability
- 154.A platform team is observing high cardinality metrics in their Prometheus setup, leading to increased storage consumption and slower query performance. Which best practice or tool can help manage this issue by reducing the number of unique label combinations while retaining critical information?Cloud Native Observability
- 155.A developer needs to instrument their new Go application to emit metrics, logs, and traces in a vendor-agnostic format, allowing them to switch observability backends (e.g., Prometheus, Jaeger, Elasticsearch) without modifying application code. Which CNCF project provides a set of APIs, SDKs, and tools for this purpose?Cloud Native Observability
- 156.A company is migrating its monolithic application to a microservices architecture on Kubernetes. They are experiencing increased latency and errors, but it's difficult to pinpoint which specific service or interaction is causing the problem. Which observability strategy would be most effective in identifying the exact path a request takes through the multiple services and the time spent in each?Cloud Native Observability
- 157.A cloud-native application is experiencing high latency in one of its critical API endpoints. Developers suspect the issue might be due to a specific section of code within a microservice that is consuming excessive CPU cycles or memory. Which specialized observability technique, when applied to the microservice, would provide detailed insights into the runtime behavior of the code, identifying hot spots and resource bottlenecks at a function level?Cloud Native Observability
- 158.A DevOps team is setting up a centralized logging solution for their Kubernetes cluster. They need to collect logs from various sources (container stdout/stderr, application logs within files, system logs), parse them, and forward them to an Elasticsearch cluster for storage and analysis. Which CNCF-graduated project is specifically designed for this log collection and forwarding purpose?Cloud Native Observability
- 159.A platform engineering team wants to implement a robust alerting system for their Kubernetes applications. They require the ability to define complex alerting rules based on Prometheus metrics, group similar alerts to prevent notification storms, and route alerts to different teams via various channels (e.g., Slack, PagerDuty) based on severity. Which component of the Prometheus ecosystem is responsible for these functionalities?Cloud Native Observability
- 160.A large enterprise with multiple development teams and Kubernetes clusters needs a highly scalable, multi-tenant solution for long-term storage and querying of Prometheus metrics. They want to avoid managing individual Prometheus servers for each cluster and enable cross-cluster querying. Which CNCF-graduated project addresses these specific requirements?Cloud Native Observability
- 161.A platform team is setting up a comprehensive alerting system for their Kubernetes cluster. They need a tool that can receive alerts from various monitoring sources (like Prometheus), group similar alerts to prevent notification storms, de-duplicate them, and route them to appropriate receivers (e.g., PagerDuty, Slack) based on custom rules. Which component is specifically designed to manage and route these alerts?Cloud Native Observability
- 162.A software development team is building a new cloud-native application using serverless functions and message queues. They need to implement an observability solution that can track the full lifecycle of a user request, even when it spans multiple asynchronous services and event-driven interactions, where direct HTTP request-response chains are often broken. Which concept is crucial for achieving this end-to-end visibility in such an architecture?Cloud Native Observability
- 163.A developer is writing a YAML manifest for a Pod and wants to ensure that a specific command is executed within the container when it starts, overriding the default command provided by the Docker image. Which field in the Pod's container specification should be used for this purpose?Kubernetes Fundamentals
- 164.A cluster operator is investigating why a Pod is stuck in a 'Pending' state. After checking the Pod's events, they see messages indicating 'FailedScheduling'. Which Kubernetes control plane component is responsible for making decisions about which Node a new Pod should run on, and therefore would report such a failure?Kubernetes Fundamentals
- 165.A cluster operator is investigating network connectivity issues within a Kubernetes cluster. They notice that Pods within a specific Deployment can communicate with each other, but they cannot reach Pods in a different Namespace, even though both Deployments are exposed via ClusterIP Services. What is the most likely reason for this isolation?Kubernetes Fundamentals
- 166.A cluster administrator is reviewing the architecture of a Kubernetes cluster. They observe that a critical component responsible for storing the cluster's state and configuration data is a highly available, distributed key-value store. Which component are they observing?Kubernetes Fundamentals
- 167.A developer is deploying a new web application to a Kubernetes cluster and wants to ensure that the application's Pods are only scheduled on worker nodes that have GPUs available. Which Kubernetes feature should be used in the Pod's manifest to achieve this?Kubernetes Fundamentals
- 168.A developer is writing a YAML manifest for a Pod and wants to ensure that a specific command is executed when the container starts, overriding the default command provided by the Docker image. Which field within the container specification should be used for this purpose?Kubernetes Fundamentals
- 169.A cluster administrator is setting up a new Kubernetes cluster and wants to ensure that specific sensitive configuration data, such as database credentials, are securely stored and accessible only by authorized Pods. Which Kubernetes object is designed for this purpose?Kubernetes Fundamentals
- 170.A developer is writing a YAML manifest for a new Pod that needs to run a container. The container image is hosted on Docker Hub. Which field in the Pod specification should be used to specify the image name and tag (e.g., `nginx:latest`) for the container?Kubernetes Fundamentals
- 171.A developer is writing a YAML manifest for a Pod and wants to ensure that a specific container within that Pod always starts with a particular environment variable, `APP_ENV`, set to `production`. Which section of the Pod's manifest should be used to define this environment variable for the container?Kubernetes Fundamentals
- 172.A DevOps engineer is troubleshooting a Pod that is exhibiting unexpected behavior. They need to get a detailed view of the Pod's current state, including events, conditions, and resource usage. Which `kubectl` command would provide this comprehensive information?Kubernetes Fundamentals
- 173.A developer has created a YAML manifest for a Pod and applied it to the cluster. The Pod is running, but they are unable to access the application inside the Pod from outside the cluster. They want to set up a basic, quick way to expose the Pod's application on a specific port on each of the cluster's worker nodes for testing purposes. Which type of Service should they create?Kubernetes Fundamentals
- 174.A developer needs to create a new Kubernetes object from a YAML file named `config.yaml`. They want to ensure that if the object already exists, it will be updated to reflect the changes in the file, and if it doesn't exist, it will be created. Which `kubectl` command should they use for this operation?Kubernetes Fundamentals
- 175.A DevOps engineer is troubleshooting a Pod that is exhibiting high latency when communicating with an external database. The Pod's YAML manifest includes a `hostNetwork: true` setting. How does this setting affect the Pod's networking?Kubernetes Fundamentals
- 176.A platform engineer is performing maintenance on a Kubernetes worker node and needs to temporarily prevent new Pods from being scheduled onto it without affecting existing running Pods. Which `kubectl` command should be used?Kubernetes Fundamentals
- 177.A developer is configuring a Pod that needs to store data persistently even if the Pod restarts or is moved to a different node. They want to request a specific amount of storage from the cluster. Which Kubernetes object is used by a Pod to claim a piece of persistent storage?Kubernetes Fundamentals
- 178.A network engineer wants to expose a web application running in a Kubernetes cluster to external traffic on a specific port (e.g., port 30080) across all worker nodes. Clients should be able to access the application by hitting any worker node's IP address on this designated port. Which Kubernetes Service type is most suitable for this requirement?Kubernetes Fundamentals
- 179.A developer needs to deploy a database application that requires stable, unique network identifiers and ordered scaling/updates for its Pods. Which Kubernetes workload object is specifically designed to manage such stateful applications?Kubernetes Fundamentals
- 180.A cluster administrator is examining the `kube-system` namespace and notices a Pod named `kube-controller-manager-node1`. What is the primary role of the `kube-controller-manager` component in a Kubernetes cluster?Kubernetes Fundamentals
- 181.A DevOps engineer is configuring a Kubernetes Deployment for a new application. They want to ensure that if a Pod's container exits with an error, Kubernetes attempts to restart it. However, if the container exits successfully, it should not be restarted. Which `restartPolicy` value should be set in the Pod's specification?Kubernetes Fundamentals
- 182.A developer is configuring a Pod that needs to access files from a shared network storage system. The storage system supports the Network File System (NFS) protocol. Which type of Kubernetes Volume should be configured in the Pod's YAML manifest to mount this NFS share?Kubernetes Fundamentals
- 183.A cluster operator is troubleshooting network issues with a Pod that is part of a Deployment. The Pod's containers are running, but other Pods cannot reach it by its Service name. The operator suspects an issue with the Pod's labels not matching the Service's selector. Which section of the Pod's YAML manifest is responsible for defining the labels that a Service uses to identify its target Pods?Kubernetes Fundamentals
- 184.A cluster administrator needs to ensure that a specific set of Pods can only communicate with other Pods within the same namespace, and deny all traffic from Pods in different namespaces. Which Kubernetes resource should they use to enforce this network segmentation?Kubernetes Fundamentals
- 185.A developer is writing a YAML manifest for a Pod and wants to ensure that a specific command is executed within the container, overriding the default command provided by the Docker image. Which field in the Pod's container specification should be used for this purpose?Kubernetes Fundamentals
- 186.A cluster operator is investigating why a newly created Pod remains in the 'Pending' state indefinitely. They have verified that the Pod's YAML is correct and there are available resources on worker nodes. Which control plane component is most likely failing or misconfigured, preventing the Pod from being assigned to a node?Kubernetes Fundamentals
- 187.A security auditor is reviewing the architecture of a Kubernetes cluster. They observe that the `kube-apiserver` component is running and accessible. Which of the following statements accurately describes the primary function of the `kube-apiserver` in a Kubernetes cluster?Kubernetes Fundamentals
- 188.A developer needs to deploy a batch job in Kubernetes that runs a series of computations and then exits successfully. The job should not automatically restart if it completes its task. Which kind of Kubernetes object is best suited for this one-time, finite task?Kubernetes Fundamentals
- 189.A new container image has been pushed to a registry, and a developer needs to update an existing Deployment named `frontend-app` to use this new image. The Deployment currently uses `my-app:v1.0`, and the new image is `my-app:v2.0`. Which `kubectl` command would efficiently update the container image without manually editing the YAML manifest?Kubernetes Fundamentals
- 190.A security auditor is reviewing a Kubernetes cluster's architecture. They are particularly interested in the component responsible for storing the cluster's configuration data, state, and metadata, which acts as the 'source of truth' for the entire cluster. Which Kubernetes control plane component fulfills this role?Kubernetes Fundamentals
- 191.A developer is configuring a Pod that needs to access files from a shared network storage system, specifically an NFS (Network File System) share. Which type of Kubernetes Volume should be used to mount this NFS share into the Pod?Kubernetes Fundamentals
- 192.A cluster operator is observing high resource usage on one of their Kubernetes worker nodes. They need to temporarily prevent new Pods from being scheduled onto this specific node while allowing existing Pods to continue running. Which `kubectl` command should be used?Kubernetes Fundamentals
- 193.A developer needs to configure a Pod that requires stable, unique network identifiers (hostnames) and persistent storage that follows the Pod's lifecycle, even through rescheduling. Which Kubernetes workload object is designed for this specific requirement?Kubernetes Fundamentals
- 194.A security engineer is reviewing the default access controls within a Kubernetes cluster. They want to understand how permissions are granted to users and ServiceAccounts for interacting with Kubernetes API resources. Which mechanism is used for this purpose?Kubernetes Fundamentals
- 195.A platform engineer is designing the network for a new microservice in Kubernetes. They need to ensure that internal services can communicate with this microservice using a stable DNS name, but the microservice should not be directly exposed to external traffic. Which type of Kubernetes Service should be used?Kubernetes Fundamentals
- 196.A cluster operator wants to ensure that a specific Pod is always scheduled on a node that has a GPU, which is identified by a custom label `gpu=true`. Which section of the Pod's YAML manifest should be configured to enforce this placement constraint?Kubernetes Fundamentals
- 197.A cluster operator needs to check the version of both the Kubernetes client (kubectl) and the server components (kube-apiserver, kubelet). Which `kubectl` command should they use to retrieve this information?Kubernetes Fundamentals
- 198.A cluster administrator needs to inspect the current configuration of the 'nginx-deployment' Deployment in the 'default' namespace, including its labels, selectors, and container images. Which `kubectl` command should the administrator use?Kubernetes Fundamentals
- 199.A developer is writing a YAML manifest for a Pod and wants to ensure that a specific container within the Pod continues to run even if the initial command fails or completes. Which field should they configure to achieve this behavior?Kubernetes Fundamentals
- 200.A cluster administrator is performing maintenance on a Kubernetes worker node and needs to temporarily prevent new Pods from being scheduled onto it without removing existing Pods. Which `kubectl` command should be used?Kubernetes Fundamentals