CKA Practice Questions
Prepare for CKA with more than an answer.
- Exam fee
- $445 USD
- Questions on the exam
- 15-20 tasks
- Passing score
- 66%
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 5
- Storage10%
- Workloads & Scheduling15%
- Services & Networking20%
- Troubleshooting30%
- Cluster Architecture, Installation & Configuration25%
- 1
Workloads on a node named
node-04are reporting intermittent I/O errors, although the node is stillReady. Before you investigate, you want the scheduler to stop placing new pods onnode-04, without evicting the pods that are already running there. Which command marksnode-04as unschedulable?Show answer details
Correct answer: B
kubectl cordon node-04setsspec.unschedulable: trueon the Node. The scheduler then places no new Pods there, while the existing Pods keep running;kubectl get nodesshows the node asReady,SchedulingDisabled, andkubectl uncordonreverses it.kubectl drainalso cordons the node but then evicts its Pods, which is not wanted yet. A customNoScheduletaint only repels Pods that do not tolerate it and does not mark the node unschedulable.kubectl stop nodeis not a kubectl command. - 2
You need to schedule a batch job that runs a database cleanup script every day at 01:00 AM UTC. The job should use the
db-cleanup:1.2image. Which Kubernetes object is designed for this type of recurring task?Show answer details
Correct answer: B
A CronJob creates Jobs on a repeating schedule written in cron format (minute, hour, day of month, month, day of week), so
"0 1 * * *"means 01:00 every day. Without.spec.timeZone, kube-controller-manager interprets the schedule in its own local time zone; set.spec.timeZone: "Etc/UTC"to make sure the job runs at 01:00 UTC. A Deployment or StatefulSet runs long-lived Pods, and a Job runs only once. - 3
When configuring a HorizontalPodAutoscaler (HPA) to scale on CPU or memory utilization, the resource metrics API (
metrics.k8s.io), which is usually provided by the metrics-server add-on, must be available in the cluster. True or False?Show answer details
Correct answer: A
True. For CPU and memory utilization the HPA controller queries the resource metrics API (
metrics.k8s.io), an aggregated API that is usually served by Metrics Server, an add-on that has to be deployed separately. Without an implementation of that API the HPA cannot read Pod usage and takes no scaling action. Custom and external metrics come from separate APIs (custom.metrics.k8s.ioandexternal.metrics.k8s.io). - 4
A cluster is experiencing issues where containers in several pods are being killed with the reason
OOMKilledwhenever their node runs low on memory. An investigation reveals that these pods have noresourcessection defined in their manifests. In which Quality of Service (QoS) class are these pods running, and why does this make them the first candidates to be killed or evicted under node memory pressure?Show answer details
Correct answer: A
A Pod in which no container has CPU or memory requests or limits is in the
BestEffortQoS class. When the node runs out of memory before the kubelet can reclaim it, the kernel OOM killer picks victims byoom_score. The kubelet gives BestEffort containersoom_score_adj1000, the highest value (Guaranteed containers get -997), so they are killed first and reportOOMKilled. For node-pressure eviction, the kubelet first ranks Pods whose usage exceeds their requests, then by Priority. A BestEffort Pod has no requests, so any usage exceeds them, and 'the kubelet prefers to evict BestEffort Pods'. An OOM kill is not an eviction: the container is terminated and can be restarted according torestartPolicy, whereas an evicted Pod ends in phaseFailedwith reasonEvicted. Setting requests (and limits) moves these Pods to Burstable or Guaranteed. - 5
You are using Kustomize to manage deployments across different environments (staging and production). The
base/directory contains a standard Deployment manifest. You need to create aproduction/overlay that increases the replica count to 5 and adds an annotationenv: production. Which of the followingkustomization.yamlfiles, placed in theproduction/directory, would achieve this?Show answer details
Correct answer: C
This is the correct syntax for a Kustomize overlay. The
resourcesfield points to the base configuration. Thereplicasfield is a special transformer that finds a resource by name and sets its replica count.commonAnnotationsis another transformer that adds the specified annotation to all resources managed by this kustomization. - 6
You are hardening a high-availability cluster whose control plane nodes run stacked etcd. After inspecting the static pod manifests in
/etc/kubernetes/manifests/, you notice theetcdpod definition is missing a critical parameter for secure communication between members. Which of the following parameters, when correctly configured, ensures that etcd members properly authenticate each other?Show answer details
Correct answer: D
--peer-client-cert-auth=truemakes an etcd member check that every incoming peer request (port 2380) presents a valid client certificate signed by the peer CA (--peer-trusted-ca-file). The flag defaults tofalse, and the etcd docs recommend enabling it to block unauthenticated, forged peers. kubeadm sets it totruein the etcd static Pod, together with--peer-cert-fileand--peer-key-file.--listen-client-urlsand--advertise-client-urlsconcern client traffic on port 2379, and--initial-cluster-state(neworexisting) only matters when a member bootstraps. - 7
A developer reports that their pod in the
dev-nsnamespace cannot resolve the service namedb-service.prod-ns.svc.cluster.local, despite the service existing and being accessible from pods within theprod-nsnamespace. You suspect a NetworkPolicy is interfering. Which of the following NetworkPolicy manifests is the most likely cause of this specific DNS resolution failure?Show answer details
Correct answer: A
When a NetworkPolicy selects Pods for egress, as a default deny-all egress policy in
dev-nsdoes, those Pods may open only the connections that some egress rule allows. The docs caution that 'a default deny-all egress policy also blocks DNS traffic'. Queries fromdev-nsPods to the cluster DNS Service (CoreDNS inkube-system, UDP/TCP port 53) are therefore dropped, and even the FQDNdb-service.prod-ns.svc.cluster.localcannot be resolved. The fix is an egress rule that allows port 53 to the CoreDNS Pods, for examplenamespaceSelectorkubernetes.io/metadata.name: kube-systempluspodSelectork8s-app: kube-dns. The other policies do not touch the lookup: ingress rules inprod-nsor ondev-nsPods do not filter the outgoing DNS query, and an egress policy inprod-nsonly affects Pods inprod-ns. - 8
You are performing a cluster upgrade from v1.32.5 to v1.33.1 using
kubeadm. After successfully upgrading the first control plane node withkubeadm upgrade apply v1.33.1, you proceed to upgrade the worker nodes. The worker's apt source already points to thepkgs.k8s.iov1.33 repository (package index updated), and the Kubernetes packages are not on hold. What is the correct sequence of commands to safely upgrade a worker node namedworker-01?Show answer details
Correct answer: C
Worker nodes are upgraded one at a time after the control plane. Drain the node (from a machine with an admin kubeconfig) and upgrade the kubeadm package. Then run
kubeadm upgrade node; on a worker it fetches the kubeadm ClusterConfiguration and upgrades the node's kubelet configuration. Upgrade the kubelet and kubectl packages, restart the kubelet and uncordon the node. pkgs.k8s.io package versions look like1.33.1-1.1, and the docs pin them as'1.33.x-*'. The v1.35 'Upgrading Linux nodes' page drains afterkubeadm upgrade nodeand runssystemctl daemon-reloadbefore restarting the kubelet; draining first is equally safe. The other sequences are wrong. Skipping the drain disrupts running workloads. Upgrading only the kubelet skipskubeadm upgrade node, so the node's kubelet configuration is not upgraded.kubeadm upgrade noderuns on the node being upgraded; it cannot target a worker from a control plane node. - 9
A pod is in a
CrashLoopBackOffstate. Runningkubectl logs --previousshows that the application terminated due to a failure to connect to a database. You need to gain interactive access to the pod's environment to test network connectivity using tools likepingandwget, but these tools are not included in the original container image. What is the most effectivekubectlcommand to debug this issue?Show answer details
Correct answer: D
kubectl debugis built for this.kubectl execneeds a running container that already contains the tools, and here the container keeps crashing and lacks them.kubectl attachonly connects to the existing process's streams, andport-forwardtunnels traffic from your workstation.kubectl debug -it --image=busybox:1.28 --share-processes --copy-to=debug-podcreates a copy of the Pod nameddebug-podwith an extra busybox container (which providesping,wget,ncandnslookup) and attaches to it. All containers in the copy share its network namespace, so you can test connectivity to the database from the application's network environment, and--share-processeslets you see the application's processes. The copy is a new Pod with its own IP and, unless you add--keep-labels, without the original labels. To debug inside the original Pod instead, add an ephemeral container withkubectl debug -it --image=busybox:1.28 --target=. Deletedebug-podwhen you are finished. - 10
You need to create a Kubernetes secret named
db-credentialsin thebackendnamespace to store a database username and password. The username isadminand the password isS3cur3P@ssw0rd!. Which imperative command correctly creates this secret directly from the command line, without first writing the credentials to a file?Show answer details
Correct answer: C
kubectl create secret genericwith one--from-literal=key=valueper key is the documented way to create a Secret from raw data. The password is wrapped in single quotes so that the shell does not interpret special characters such as!or$. The second command stores the wrong password value (the echoed textpassword: S3cur3P@ssw0rd!plus a newline),kubectl create secrethas no--username/--passwordflags and needs a subcommand such asgeneric, and--from-env-fileneeds a credentials file written beforehand. Values passed on the command line can end up in your shell history, so clear or avoid the history entry when handling real credentials.
