Kubernetes and Cloud Native Associate (KCNA) practice questions
230 free questions with answers and explanations.
- 201.A developer is writing a YAML manifest for a Pod and wants to ensure that a specific command is executed within the container, overriding the default command provided by the Docker image. Which field in the Pod's container specification should be used for this purpose?Kubernetes Fundamentals
- 202.A cluster operator is investigating why a newly created Pod remains in the 'Pending' state indefinitely. They have verified that the Pod's YAML is correct and there are available resources on worker nodes. Which control plane component is most likely failing or misconfigured, preventing the Pod from being assigned to a node?Kubernetes Fundamentals
- 203.A security auditor is reviewing the architecture of a Kubernetes cluster. They observe that the `kube-apiserver` component is running and accessible. Which of the following statements accurately describes the primary function of the `kube-apiserver` in a Kubernetes cluster?Kubernetes Fundamentals
- 204.A developer needs to deploy a batch job in Kubernetes that runs a series of computations and then exits successfully. The job should not automatically restart if it completes its task. Which kind of Kubernetes object is best suited for this one-time, finite task?Kubernetes Fundamentals
- 205.A new container image has been pushed to a registry, and a developer needs to update an existing Deployment named `frontend-app` to use this new image. The Deployment currently uses `my-app:v1.0`, and the new image is `my-app:v2.0`. Which `kubectl` command would efficiently update the container image without manually editing the YAML manifest?Kubernetes Fundamentals
- 206.A security auditor is reviewing a Kubernetes cluster's architecture. They are particularly interested in the component responsible for storing the cluster's configuration data, state, and metadata, which acts as the 'source of truth' for the entire cluster. Which Kubernetes control plane component fulfills this role?Kubernetes Fundamentals
- 207.A developer is configuring a Pod that needs to access files from a shared network storage system, specifically an NFS (Network File System) share. Which type of Kubernetes Volume should be used to mount this NFS share into the Pod?Kubernetes Fundamentals
- 208.A cluster operator is observing high resource usage on one of their Kubernetes worker nodes. They need to temporarily prevent new Pods from being scheduled onto this specific node while allowing existing Pods to continue running. Which `kubectl` command should be used?Kubernetes Fundamentals
- 209.A DevOps engineer is troubleshooting a Pod that is exhibiting unexpected behavior. They need to get a detailed view of the Pod's current state, including events, conditions, and resource usage. Which `kubectl` command would provide this comprehensive information?Kubernetes Fundamentals
- 210.A developer has created a YAML manifest for a Pod and applied it to the cluster. The Pod is running, but they are unable to access the application inside the Pod from outside the cluster. They want to set up a basic, quick way to expose the Pod's application on a specific port on each of the cluster's worker nodes for testing purposes. Which type of Service should they create?Kubernetes Fundamentals
- 211.A developer needs to create a new Kubernetes object from a YAML file named `config.yaml`. They want to ensure that if the object already exists, it will be updated to reflect the changes in the file, and if it doesn't exist, it will be created. Which `kubectl` command should they use for this operation?Kubernetes Fundamentals
- 212.A DevOps engineer is troubleshooting a Pod that is exhibiting high latency when communicating with an external database. The Pod's YAML manifest includes a `hostNetwork: true` setting. How does this setting affect the Pod's networking?Kubernetes Fundamentals
- 213.A security auditor is reviewing the architecture of a Kubernetes cluster. They observe that a critical component is responsible for storing the cluster's state, configuration, and metadata, acting as the cluster's single source of truth. Which component are they referring to?Kubernetes Fundamentals
- 214.A cluster operator needs to check the current version of the Kubernetes client and server components to ensure compatibility and identify any potential upgrade issues. Which `kubectl` command would provide this information?Kubernetes Fundamentals
- 215.A developer needs to execute a one-off, short-lived task in a Kubernetes cluster, such as running a database migration script or a data processing batch job. This task should run to completion and then terminate. Which Kubernetes workload object is most suitable for this use case?Kubernetes Fundamentals
- 216.A security auditor is reviewing a Kubernetes cluster and wants to ensure that sensitive information, such as database credentials, is stored securely and injected into Pods without being exposed in plain text within YAML manifests or environment variables. Which Kubernetes resource is designed for this purpose?Kubernetes Fundamentals
- 217.A cluster operator is observing that a newly created Pod remains in the 'Pending' state indefinitely. Which of the following components is primarily responsible for assigning Pods to Nodes, and its malfunction could cause this issue?Kubernetes Fundamentals
- 218.A developer needs to execute a one-off, short-lived task in a Kubernetes cluster, such as a database migration script or a batch processing job. This task should run to completion and then terminate. Which type of Kubernetes workload object is most suitable for this scenario?Kubernetes Fundamentals
- 219.A cluster operator is observing unusual network traffic patterns within a Kubernetes cluster. They suspect a misconfigured Pod is attempting to communicate with unauthorized external services. Which Kubernetes resource, when applied, can restrict outbound network traffic from specific Pods?Kubernetes Fundamentals
- 220.A cluster operator is observing that newly created Pods are consistently stuck in the 'Pending' state. They suspect an issue with resource availability on the worker nodes. Which Kubernetes control plane component is primarily responsible for assigning Pods to nodes?Kubernetes Fundamentals
- 221.A cluster operator is configuring a new Kubernetes cluster and wants to ensure that all internal communication between Pods is encrypted by default. Which networking component or feature would be primarily responsible for enforcing such a policy?Kubernetes Fundamentals
- 222.A security auditor is reviewing the default access controls within a Kubernetes cluster. They notice that individual users and service accounts are granted specific permissions to perform actions on Kubernetes resources like Pods, Deployments, and Services. Which Kubernetes security mechanism is primarily responsible for defining and enforcing these permissions?Kubernetes Fundamentals
- 223.A developer needs to create a Kubernetes object that will run a containerized application, ensuring that the application scales automatically based on CPU utilization. Which Kubernetes object is most appropriate for this requirement?Kubernetes Fundamentals
- 224.A developer is writing a YAML manifest for a Pod and wants to ensure that a specific container within that Pod always runs with a specific command and arguments, overriding the default command provided by the container image. Which field in the Pod definition should they configure for this purpose?Kubernetes Fundamentals
- 225.A developer attempts to create a Pod using a YAML manifest, but it consistently fails to start with an 'ImagePullBackOff' error. They verify that the container image name is correct. What is the most likely reason for this error, assuming the image name is accurate?Kubernetes Fundamentals
- 226.A developer is creating a YAML manifest for a Pod that needs to run a simple web server. Which core Kubernetes object is the smallest deployable unit that can contain this container?Kubernetes Fundamentals
- 227.A security engineer is reviewing the default access controls within a Kubernetes cluster. They want to understand how permissions for users and service accounts are defined and enforced across different resources and namespaces. Which Kubernetes authorization mechanism is primarily responsible for this?Kubernetes Fundamentals
- 228.A developer wants to create a Kubernetes object that ensures a single instance of a specific Pod runs on every worker node in the cluster, primarily for collecting logs or monitoring metrics. Which Kubernetes object is designed for this use case?Kubernetes Fundamentals
- 229.A developer is preparing a YAML manifest for a new Kubernetes Pod. They intend for this Pod to run a container that executes a single, short-lived task to completion and then terminate. Which of the following Kubernetes object types is most appropriate for defining this kind of workload?Kubernetes Fundamentals
- 230.A developer is preparing to deploy a new stateless application to a Kubernetes cluster. The application requires multiple identical instances for high availability and automatic scaling. Which Kubernetes object is most appropriate for defining and managing these instances?Kubernetes Fundamentals