KubeRusted
Spinning up your cluster…

KCNA exam prep — Kubernetes and Cloud Native Associate

Free KCNA (Kubernetes and Cloud Native Associate) practice: the 4 official domains, exam-style questions, a timed practice exam and more.

Play the KCNA map → · Official KCNA exam page

Kubernetes Fundamentals (44%)

Core concepts, administration, scheduling and containerization

Container Orchestration (28%)

Networking, security, troubleshooting and storage

Cloud Native Application Delivery (16%)

Application delivery (CI/CD, GitOps, packaging) and debugging

Cloud Native Architecture (12%)

Observability, ecosystem and principles, community and collaboration

Practice questions

Which component is the only one that talks to etcd directly?

Answer: kube-apiserver. Every other component reads and writes cluster state through the API server; only it talks to etcd.

Which node component makes sure the containers described in a Pod are running and healthy?

Answer: kubelet. The kubelet on each node watches for Pods assigned to it and drives the container runtime.

Which component implements Kubernetes Service networking on each node (iptables, IPVS or nftables rules)?

Answer: kube-proxy. kube-proxy programs the node so traffic to a Service IP reaches a backing Pod (some CNIs replace it).

Which control-plane component runs controllers such as the Deployment, ReplicaSet and Node controllers?

Answer: kube-controller-manager. kube-controller-manager bundles the core control loops into one binary.

Which component integrates Kubernetes with a cloud provider’s load balancers and node lifecycle?

Answer: cloud-controller-manager. Cloud-specific control loops (nodes, routes, LoadBalancer Services) live in the cloud-controller-manager.

What does a Deployment manage directly?

Answer: ReplicaSets. A Deployment owns ReplicaSets, and each ReplicaSet owns Pods. Rolling updates swap between ReplicaSets.

Which workload resource gives each Pod a stable network identity and its own persistent storage?

Answer: StatefulSet. StatefulSet Pods get ordinal names (db-0, db-1) and per-Pod PersistentVolumeClaims.

Which workload runs one Pod on every (matching) node, e.g. a log collector?

Answer: DaemonSet. A DaemonSet places one Pod per eligible node and follows nodes as they join or leave.

Which workload runs Pods until a task completes successfully?

Answer: Job. Jobs track completions; a CronJob creates Jobs on a schedule.

What is the role of a ReplicaSet?

Answer: Keep a specified number of identical Pods running. A ReplicaSet reconciles the number of matching Pods to its replicas field.

Which command shows the API resource types (kinds) the cluster serves?

Answer: kubectl api-resources. kubectl api-resources lists every served resource with its short name, API group and whether it is namespaced.

Which command prints documentation for the fields of a resource, e.g. a Pod spec?

Answer: kubectl explain pod.spec. kubectl explain reads the API schema and documents each field.

Which of these are cluster-scoped (not namespaced) resources?

Answer: Node; PersistentVolume; Namespace. Nodes, PersistentVolumes and Namespaces exist cluster-wide; Pods, Services and ConfigMaps live inside a namespace.

Every Kubernetes object has two nested fields describing what you want and what exists. What are they?

Answer: spec and status. You write spec (desired state); controllers report status (observed state).

What are annotations used for?

Answer: Non-identifying metadata, often read by tools. Labels identify and select objects; annotations store arbitrary metadata such as build info or tool configuration.

What does the scheduler use to decide whether a Pod fits on a node?

Answer: The Pod’s resource requests and the node’s allocatable capacity. Scheduling is based on requests (plus constraints like affinity and taints), not on live usage.

A node has the taint dedicated=gpu:NoSchedule. Which Pods can be scheduled onto it?

Answer: Pods with a matching toleration. A taint repels Pods unless they tolerate it. Tolerations allow, they do not attract.

How do you make a Pod run only on nodes labelled disktype=ssd?

Answer: nodeSelector or required node affinity on disktype=ssd. nodeSelector and requiredDuringScheduling… node affinity are hard placement constraints.

What happens to Pods on a node if you run kubectl drain on it?

Answer: They are evicted (respecting PodDisruptionBudgets) and the node is cordoned. Drain cordons the node and evicts Pods so their controllers recreate them elsewhere.

Which command marks a node unschedulable without evicting its Pods?

Answer: kubectl cordon. cordon only stops new Pods from landing; drain also evicts the existing ones.

What does a PodDisruptionBudget protect against?

Answer: Voluntary disruptions such as drains removing too many Pods at once. PDBs limit how many replicas can be down due to voluntary evictions.

What is the standard that defines container image and runtime formats?

Answer: The Open Container Initiative (OCI) specifications. OCI defines the image, runtime and distribution specs that tools like Docker, containerd and Podman follow.

What makes containers lighter than virtual machines?

Answer: They share the host kernel instead of each running a guest OS. Containers are isolated processes (namespaces, cgroups) on a shared kernel.

Which Linux features isolate and limit containers?

Answer: Namespaces; cgroups. Namespaces isolate what a process sees; cgroups limit what it can use.

Why pin an image by digest (image@sha256:…) rather than a tag?

Answer: A digest is immutable; a tag can be moved to different content. Tags like :latest can change under you; a digest always identifies the same bytes.

What does imagePullPolicy: Always do?

Answer: The kubelet checks the registry for the image every time it starts a container. Always re-resolves the image reference on every container start (using the cache when the digest matches).

What is a multi-container Pod sidecar typically used for?

Answer: A helper process (proxy, log shipper) sharing the Pod’s network and volumes. Containers in a Pod share an IP and can share volumes, which is what makes sidecars work.

How do containers in the same Pod usually talk to each other?

Answer: Over localhost. All containers in a Pod share one network namespace.

Which kubectl command applies a declarative YAML manifest?

Answer: kubectl apply -f app.yaml. kubectl apply creates or updates objects to match the file.

What is the difference between `kubectl create` and `kubectl apply`?

Answer: create fails if the object exists; apply creates or updates it. apply is declarative and idempotent; create is an imperative one-shot.

Where does kubectl find the cluster address and credentials by default?

Answer: ~/.kube/config (or $KUBECONFIG). kubeconfig files hold clusters, users and contexts; KUBECONFIG can point at others.

Which kubectl command switches the active cluster/user/namespace combination?

Answer: kubectl config use-context. Contexts bundle a cluster, a user and a default namespace.

What is a static Pod?

Answer: A Pod managed directly by a kubelet from a manifest file on its node. kubeadm runs control-plane components as static Pods from /etc/kubernetes/manifests.

What is the purpose of the kube-system namespace?

Answer: Objects created by the Kubernetes system itself, such as CoreDNS. System components and add-ons run in kube-system.

Which object grants a Pod an identity for calling the Kubernetes API?

Answer: ServiceAccount. Pods authenticate to the API as their ServiceAccount; RBAC then decides what it may do.

Which Service type gives a Service an internal-only virtual IP (the default)?

Answer: ClusterIP. ClusterIP is reachable only inside the cluster.

What does a Service of type ExternalName do?

Answer: Returns a DNS CNAME to an external hostname. ExternalName maps the Service name to an external DNS name; no proxying happens.

What is a headless Service (clusterIP: None) used for?

Answer: DNS returns the individual Pod IPs instead of one virtual IP. Headless Services are common with StatefulSets so clients can reach specific Pods.

Which resource routes external HTTP(S) traffic to Services by host and path?

Answer: Ingress. An Ingress (implemented by an Ingress controller) maps hosts and paths to Services.

What is the Gateway API?

Answer: A role-oriented successor to Ingress with Gateway and route resources. Gateway API splits infrastructure (GatewayClass, Gateway) from routing (HTTPRoute and friends).

By default, can any Pod reach any other Pod in the cluster?

Answer: Yes — Pod networking is open until NetworkPolicies restrict it. Kubernetes networking is flat and allow-all by default.

What is required for NetworkPolicies to take effect?

Answer: A network plugin (CNI) that enforces them. NetworkPolicy is just an API object; the CNI implements it.

Which component provides DNS names like my-svc.my-ns.svc.cluster.local?

Answer: CoreDNS. CoreDNS watches Services and Pods and answers cluster DNS queries.

What does CSI stand for and what does it do?

Answer: Container Storage Interface — lets storage vendors plug volume drivers into Kubernetes. CSI drivers provision and attach volumes outside the Kubernetes codebase.

What does a StorageClass describe?

Answer: A class of storage and how to provision it dynamically. A PVC that names a StorageClass gets a volume provisioned by that class’s provisioner.

Which access mode allows a volume to be mounted read-write by many nodes?

Answer: ReadWriteMany. RWX needs storage that supports it, such as NFS or CephFS.

What happens to an emptyDir volume when its Pod is deleted?

Answer: Its data is deleted too. emptyDir lives exactly as long as the Pod.

What is the difference between a PersistentVolume and a PersistentVolumeClaim?

Answer: A PV is the storage resource; a PVC is a request that binds to one. Pods mount claims; claims bind to volumes (possibly provisioned on demand).

What does RBAC’s Role grant?

Answer: Permissions (verbs on resources) within one namespace. Role is namespaced; ClusterRole is cluster-wide.

How are Kubernetes Secrets stored in etcd by default?

Answer: Base64-encoded but not encrypted, unless encryption at rest is configured. Enable encryption at rest and restrict access with RBAC to protect them.

Which Pod Security Standard is the most restrictive?

Answer: restricted. privileged → baseline → restricted, enforced by Pod Security Admission per namespace.

A Pod is Pending. What is the first command to find out why?

Answer: kubectl describe pod <name>. Pending Pods have no running container to log from; the events in describe explain scheduling failures.

A container keeps restarting with CrashLoopBackOff. Which command shows its last output?

Answer: kubectl logs <pod> --previous. --previous shows the logs of the crashed container instance.

A container was killed with reason OOMKilled. What happened?

Answer: It exceeded its memory limit. Exceeding a memory limit gets the container killed; exceeding a CPU limit only throttles it.

Which command opens a shell inside a running container?

Answer: kubectl exec -it <pod> -- sh. exec runs a command in an existing container; -it makes it interactive.

What does kubectl port-forward do?

Answer: Forwards a local port to a port on a Pod or Service. Handy for debugging without exposing anything publicly.

Which probe failure removes a Pod from Service endpoints without restarting it?

Answer: Readiness probe. Readiness controls traffic; liveness controls restarts.

What does mTLS in a service mesh provide between services?

Answer: Encryption plus mutual authentication of both workloads. Each side proves its identity with a certificate and traffic is encrypted.

What does a Deployment’s rolling update strategy do?

Answer: Replaces old Pods with new ones gradually. maxSurge and maxUnavailable control the pace; strategy Recreate stops everything first.

How do you roll a Deployment back to its previous revision?

Answer: kubectl rollout undo deployment/<name>. Deployments keep previous ReplicaSets as revisions to roll back to.

In a canary release…

Answer: a small share of traffic goes to the new version first. If the canary looks healthy, traffic is shifted gradually.

In a blue-green deployment…

Answer: the new version runs beside the old and traffic switches over in one step. Rolling back is switching traffic back to the old (blue) environment.

What is a Helm chart?

Answer: A package of templated Kubernetes manifests plus default values. helm install renders the templates with your values and tracks the release.

What does Kustomize do?

Answer: Customizes YAML with overlays and patches, without templates. Kustomize is built into kubectl (kubectl apply -k).

Which practice automatically builds and tests every code change?

Answer: Continuous integration. CI runs on every commit; CD then delivers the tested artifact.

What distinguishes GitOps from a CI job that runs kubectl apply?

Answer: An agent in the cluster pulls desired state from Git and continuously reconciles it. Pull-based, continuously reconciled delivery is the core of GitOps.

Which are CNCF graduated GitOps tools?

Answer: Argo CD; Flux. Argo CD and Flux are both graduated CNCF projects.

What is the main benefit of declarative configuration stored in Git?

Answer: A versioned, reviewable source of truth that can be re-applied any time. Every change is a commit — reviewable, auditable and revertible.

What is an artifact repository in a delivery pipeline?

Answer: Where built artifacts such as container images and charts are stored. Registries (OCI) hold images and charts that deployments reference.

Why should a pipeline deploy the same image to staging and production?

Answer: So what was tested is exactly what runs in production. Build once, promote the same artifact — rebuilding could change it.

What does horizontal scaling mean?

Answer: Adding or removing instances (Pods or nodes). HPA scales horizontally; VPA adjusts the size of each Pod.

Which component adds nodes when Pods cannot be scheduled for lack of capacity?

Answer: Cluster Autoscaler (or Karpenter). Node autoscalers react to unschedulable Pods by provisioning nodes.

What does a microservices architecture mean?

Answer: An application split into small, independently deployable services. Each service can be built, deployed and scaled on its own.

Which CNCF graduated project is a service mesh?

Answer: Linkerd. Linkerd and Istio are graduated service meshes; the others are not meshes.

What does an OpenTelemetry Collector do?

Answer: Receives, processes and exports telemetry to backends. It decouples instrumentation from the backend you send data to.

Which body governs the CNCF’s technical direction and project maturity?

Answer: The Technical Oversight Committee (TOC). The TOC accepts projects and moves them through Sandbox, Incubating and Graduated.

Where are new Kubernetes features proposed and tracked?

Answer: Kubernetes Enhancement Proposals (KEPs). KEPs document a feature from alpha through beta to GA.

Which of these are typical cloud native principles?

Answer: Declarative APIs; Immutable infrastructure; Automation and self-healing. Cloud native favours "cattle not pets": replaceable, automated, declaratively managed systems.

Which component stores the entire state of a Kubernetes cluster?

Answer: etcd. etcd is the consistent key-value store behind the API server; nothing else persists cluster state.

What is the smallest deployable unit in Kubernetes?

Answer: Pod. You never deploy a bare container — Kubernetes schedules Pods, which wrap one or more containers.

Which control-plane component decides which node a new Pod runs on?

Answer: kube-scheduler. The scheduler assigns the node; the kubelet on that node then starts the containers.

Which namespaces exist in every new cluster?

Answer: default; kube-system; kube-public. Kubernetes starts with default, kube-system, kube-public and kube-node-lease.

Which Service type exposes a Service on the same static port of every node?

Answer: NodePort. NodePort opens a port (30000–32767 by default) on every node; ClusterIP is internal-only.

Which interface lets Kubernetes use different container runtimes such as containerd or CRI-O?

Answer: CRI. CRI is for runtimes, CNI for networking, CSI for storage. OCI defines image and runtime formats, not the kubelet interface.

A Pod is stuck in ImagePullBackOff. What is the most likely cause?

Answer: The image name/tag is wrong or the registry needs credentials. ImagePullBackOff means the kubelet cannot fetch the image; `kubectl describe pod` shows the pull error.

In GitOps, how does a change reach the cluster?

Answer: An agent in the cluster pulls the desired state from Git and reconciles toward it. OpenGitOps: declarative, versioned and immutable, pulled automatically, continuously reconciled.

Which tool packages Kubernetes manifests as versioned, configurable charts?

Answer: Helm. Helm charts are templated manifests plus values; releases can be upgraded and rolled back.

How does Prometheus normally collect metrics?

Answer: It pulls (scrapes) HTTP /metrics endpoints on an interval. Prometheus is pull-based; short-lived jobs can use the Pushgateway as an exception.

What is the CNCF project maturity order?

Answer: Sandbox → Incubating → Graduated. Alpha/beta/stable describes Kubernetes feature maturity, not CNCF projects.

Which of these are the classic three signals of observability?

Answer: Metrics; Logs; Traces. Dashboards visualize signals; they are not a signal themselves.