Free KCNA (Kubernetes and Cloud Native Associate) practice: the 4 official domains, exam-style questions, a timed practice exam and more.
Play the KCNA map → · Official KCNA exam page
Core concepts, administration, scheduling and containerization
Networking, security, troubleshooting and storage
Application delivery (CI/CD, GitOps, packaging) and debugging
Observability, ecosystem and principles, community and collaboration
Answer: kube-apiserver. Every other component reads and writes cluster state through the API server; only it talks to etcd.
Answer: kubelet. The kubelet on each node watches for Pods assigned to it and drives the container runtime.
Answer: kube-proxy. kube-proxy programs the node so traffic to a Service IP reaches a backing Pod (some CNIs replace it).
Answer: kube-controller-manager. kube-controller-manager bundles the core control loops into one binary.
Answer: cloud-controller-manager. Cloud-specific control loops (nodes, routes, LoadBalancer Services) live in the cloud-controller-manager.
Answer: ReplicaSets. A Deployment owns ReplicaSets, and each ReplicaSet owns Pods. Rolling updates swap between ReplicaSets.
Answer: StatefulSet. StatefulSet Pods get ordinal names (db-0, db-1) and per-Pod PersistentVolumeClaims.
Answer: DaemonSet. A DaemonSet places one Pod per eligible node and follows nodes as they join or leave.
Answer: Job. Jobs track completions; a CronJob creates Jobs on a schedule.
Answer: Keep a specified number of identical Pods running. A ReplicaSet reconciles the number of matching Pods to its replicas field.
Answer: kubectl api-resources. kubectl api-resources lists every served resource with its short name, API group and whether it is namespaced.
Answer: kubectl explain pod.spec. kubectl explain reads the API schema and documents each field.
Answer: Node; PersistentVolume; Namespace. Nodes, PersistentVolumes and Namespaces exist cluster-wide; Pods, Services and ConfigMaps live inside a namespace.
Answer: spec and status. You write spec (desired state); controllers report status (observed state).
Answer: Non-identifying metadata, often read by tools. Labels identify and select objects; annotations store arbitrary metadata such as build info or tool configuration.
Answer: The Pod’s resource requests and the node’s allocatable capacity. Scheduling is based on requests (plus constraints like affinity and taints), not on live usage.
Answer: Pods with a matching toleration. A taint repels Pods unless they tolerate it. Tolerations allow, they do not attract.
Answer: nodeSelector or required node affinity on disktype=ssd. nodeSelector and requiredDuringScheduling… node affinity are hard placement constraints.
Answer: They are evicted (respecting PodDisruptionBudgets) and the node is cordoned. Drain cordons the node and evicts Pods so their controllers recreate them elsewhere.
Answer: kubectl cordon. cordon only stops new Pods from landing; drain also evicts the existing ones.
Answer: Voluntary disruptions such as drains removing too many Pods at once. PDBs limit how many replicas can be down due to voluntary evictions.
Answer: The Open Container Initiative (OCI) specifications. OCI defines the image, runtime and distribution specs that tools like Docker, containerd and Podman follow.
Answer: They share the host kernel instead of each running a guest OS. Containers are isolated processes (namespaces, cgroups) on a shared kernel.
Answer: Namespaces; cgroups. Namespaces isolate what a process sees; cgroups limit what it can use.
Answer: A digest is immutable; a tag can be moved to different content. Tags like :latest can change under you; a digest always identifies the same bytes.
Answer: The kubelet checks the registry for the image every time it starts a container. Always re-resolves the image reference on every container start (using the cache when the digest matches).
Answer: A helper process (proxy, log shipper) sharing the Pod’s network and volumes. Containers in a Pod share an IP and can share volumes, which is what makes sidecars work.
Answer: Over localhost. All containers in a Pod share one network namespace.
Answer: kubectl apply -f app.yaml. kubectl apply creates or updates objects to match the file.
Answer: create fails if the object exists; apply creates or updates it. apply is declarative and idempotent; create is an imperative one-shot.
Answer: ~/.kube/config (or $KUBECONFIG). kubeconfig files hold clusters, users and contexts; KUBECONFIG can point at others.
Answer: kubectl config use-context. Contexts bundle a cluster, a user and a default namespace.
Answer: A Pod managed directly by a kubelet from a manifest file on its node. kubeadm runs control-plane components as static Pods from /etc/kubernetes/manifests.
Answer: Objects created by the Kubernetes system itself, such as CoreDNS. System components and add-ons run in kube-system.
Answer: ServiceAccount. Pods authenticate to the API as their ServiceAccount; RBAC then decides what it may do.
Answer: ClusterIP. ClusterIP is reachable only inside the cluster.
Answer: Returns a DNS CNAME to an external hostname. ExternalName maps the Service name to an external DNS name; no proxying happens.
Answer: DNS returns the individual Pod IPs instead of one virtual IP. Headless Services are common with StatefulSets so clients can reach specific Pods.
Answer: Ingress. An Ingress (implemented by an Ingress controller) maps hosts and paths to Services.
Answer: A role-oriented successor to Ingress with Gateway and route resources. Gateway API splits infrastructure (GatewayClass, Gateway) from routing (HTTPRoute and friends).
Answer: Yes — Pod networking is open until NetworkPolicies restrict it. Kubernetes networking is flat and allow-all by default.
Answer: A network plugin (CNI) that enforces them. NetworkPolicy is just an API object; the CNI implements it.
Answer: CoreDNS. CoreDNS watches Services and Pods and answers cluster DNS queries.
Answer: Container Storage Interface — lets storage vendors plug volume drivers into Kubernetes. CSI drivers provision and attach volumes outside the Kubernetes codebase.
Answer: A class of storage and how to provision it dynamically. A PVC that names a StorageClass gets a volume provisioned by that class’s provisioner.
Answer: ReadWriteMany. RWX needs storage that supports it, such as NFS or CephFS.
Answer: Its data is deleted too. emptyDir lives exactly as long as the Pod.
Answer: A PV is the storage resource; a PVC is a request that binds to one. Pods mount claims; claims bind to volumes (possibly provisioned on demand).
Answer: Permissions (verbs on resources) within one namespace. Role is namespaced; ClusterRole is cluster-wide.
Answer: Base64-encoded but not encrypted, unless encryption at rest is configured. Enable encryption at rest and restrict access with RBAC to protect them.
Answer: restricted. privileged → baseline → restricted, enforced by Pod Security Admission per namespace.
Answer: kubectl describe pod <name>. Pending Pods have no running container to log from; the events in describe explain scheduling failures.
Answer: kubectl logs <pod> --previous. --previous shows the logs of the crashed container instance.
Answer: It exceeded its memory limit. Exceeding a memory limit gets the container killed; exceeding a CPU limit only throttles it.
Answer: kubectl exec -it <pod> -- sh. exec runs a command in an existing container; -it makes it interactive.
Answer: Forwards a local port to a port on a Pod or Service. Handy for debugging without exposing anything publicly.
Answer: Readiness probe. Readiness controls traffic; liveness controls restarts.
Answer: Encryption plus mutual authentication of both workloads. Each side proves its identity with a certificate and traffic is encrypted.
Answer: Replaces old Pods with new ones gradually. maxSurge and maxUnavailable control the pace; strategy Recreate stops everything first.
Answer: kubectl rollout undo deployment/<name>. Deployments keep previous ReplicaSets as revisions to roll back to.
Answer: a small share of traffic goes to the new version first. If the canary looks healthy, traffic is shifted gradually.
Answer: the new version runs beside the old and traffic switches over in one step. Rolling back is switching traffic back to the old (blue) environment.
Answer: A package of templated Kubernetes manifests plus default values. helm install renders the templates with your values and tracks the release.
Answer: Customizes YAML with overlays and patches, without templates. Kustomize is built into kubectl (kubectl apply -k).
Answer: Continuous integration. CI runs on every commit; CD then delivers the tested artifact.
Answer: An agent in the cluster pulls desired state from Git and continuously reconciles it. Pull-based, continuously reconciled delivery is the core of GitOps.
Answer: Argo CD; Flux. Argo CD and Flux are both graduated CNCF projects.
Answer: A versioned, reviewable source of truth that can be re-applied any time. Every change is a commit — reviewable, auditable and revertible.
Answer: Where built artifacts such as container images and charts are stored. Registries (OCI) hold images and charts that deployments reference.
Answer: So what was tested is exactly what runs in production. Build once, promote the same artifact — rebuilding could change it.
Answer: Adding or removing instances (Pods or nodes). HPA scales horizontally; VPA adjusts the size of each Pod.
Answer: Cluster Autoscaler (or Karpenter). Node autoscalers react to unschedulable Pods by provisioning nodes.
Answer: An application split into small, independently deployable services. Each service can be built, deployed and scaled on its own.
Answer: Linkerd. Linkerd and Istio are graduated service meshes; the others are not meshes.
Answer: Receives, processes and exports telemetry to backends. It decouples instrumentation from the backend you send data to.
Answer: The Technical Oversight Committee (TOC). The TOC accepts projects and moves them through Sandbox, Incubating and Graduated.
Answer: Kubernetes Enhancement Proposals (KEPs). KEPs document a feature from alpha through beta to GA.
Answer: Declarative APIs; Immutable infrastructure; Automation and self-healing. Cloud native favours "cattle not pets": replaceable, automated, declaratively managed systems.
Answer: etcd. etcd is the consistent key-value store behind the API server; nothing else persists cluster state.
Answer: Pod. You never deploy a bare container — Kubernetes schedules Pods, which wrap one or more containers.
Answer: kube-scheduler. The scheduler assigns the node; the kubelet on that node then starts the containers.
Answer: default; kube-system; kube-public. Kubernetes starts with default, kube-system, kube-public and kube-node-lease.
Answer: NodePort. NodePort opens a port (30000–32767 by default) on every node; ClusterIP is internal-only.
Answer: CRI. CRI is for runtimes, CNI for networking, CSI for storage. OCI defines image and runtime formats, not the kubelet interface.
Answer: The image name/tag is wrong or the registry needs credentials. ImagePullBackOff means the kubelet cannot fetch the image; `kubectl describe pod` shows the pull error.
Answer: An agent in the cluster pulls the desired state from Git and reconciles toward it. OpenGitOps: declarative, versioned and immutable, pulled automatically, continuously reconciled.
Answer: Helm. Helm charts are templated manifests plus values; releases can be upgraded and rolled back.
Answer: It pulls (scrapes) HTTP /metrics endpoints on an interval. Prometheus is pull-based; short-lived jobs can use the Pushgateway as an exception.
Answer: Sandbox → Incubating → Graduated. Alpha/beta/stable describes Kubernetes feature maturity, not CNCF projects.
Answer: Metrics; Logs; Traces. Dashboards visualize signals; they are not a signal themselves.