KCNA Practice Questions
Prepare for KCNA with more than an answer.
- Exam fee
- $250 USD
- Level
- Associate
- Valid for
- 3 years
Domains covered on the exam 5
- Kubernetes Fundamentals46%
- Container Orchestration22%
- Cloud Native Architecture16%
- Cloud Native Observability8%
- Cloud Native Application Delivery8%
- 1
A DevOps engineer is troubleshooting a Pod that is stuck in the
Pendingstate. After runningkubectl describe pod, they see the event message:0/3 nodes are available: 3 Insufficient cpu. What is the most likely cause of this issue?Show answer details
Correct answer: C
The Kubernetes scheduler is responsible for assigning Pods to Nodes. The event message
Insufficient cpudirectly indicates that the scheduler evaluated all available nodes and none of them had enough unallocated CPU capacity to meet the Pod's requested CPU amount. Image pull errors would result in a different state likeImagePullBackOff, and unresponsive kubelets would typically mark the node asNotReady. - 2
A technology steering committee is evaluating new open-source projects to include in their platform. They want to adopt technologies that are proven, stable, and have strong community support. According to the CNCF's project maturity levels, which category of projects best fits these requirements?
Show answer details
Correct answer: B
The CNCF has three project maturity levels. 'Graduated' projects (like Kubernetes, Prometheus, and Envoy) are considered the most mature, stable, and widely adopted. 'Incubating' projects are stable but still maturing. 'Sandbox' projects are for early-stage experimentation. For a committee seeking proven and stable technologies, Graduated projects are the most appropriate choice.
- 3
A security team wants to enforce a baseline security posture for all workloads in a specific namespace. They want to prevent containers from running as root and block hostPath volumes, but still allow for flexibility. Which Kubernetes security mechanism is designed for this type of policy-driven enforcement at the namespace level?
Show answer details
Correct answer: C
Pod Security Standards (PSS) are the successor to PodSecurityPolicies and define different security levels for Pods (e.g., Privileged, Baseline, Restricted). They are applied at the namespace level via labels and are enforced by the built-in Pod Security admission controller. This mechanism is specifically designed to enforce workload security postures like preventing root containers and risky volume mounts. RBAC controls access to the API, while NetworkPolicies control traffic flow.
- 4
A system administrator needs to expose a web application running in a set of Pods to external users via the internet. The cloud provider offers a native load balancer service. Which Kubernetes Service type should be used to automatically provision and integrate with the cloud provider's load balancer?
graph TD Internet((Internet)) --> CloudLB[Cloud Load Balancer] subgraph Kubernetes Cluster CloudLB --> Node1[Node 1] CloudLB --> Node2[Node 2] Node1 --> PodA[Pod A] Node2 --> PodB[Pod B] endShow answer details
Correct answer: C
The
LoadBalancerService type is the standard way to expose a service externally using a cloud provider's load balancer. When this type is used, Kubernetes communicates with the cloud provider's API to provision a load balancer, which then directs external traffic to the service's NodePorts.ClusterIPis only for internal communication,NodePortexposes the service on each node's IP but doesn't provision an external load balancer, andExternalNameis for DNS aliasing. - 5
A platform engineering team is using Argo CD for GitOps. They notice that a developer has manually changed a Deployment's image tag using
kubectl set image. The team wants to ensure the cluster state always matches the state declared in their Git repository. What core GitOps principle, when enabled in Argo CD, addresses this situation?Show answer details
Correct answer: B
This scenario describes configuration drift, where the live state of the cluster differs from the desired state in Git. A core feature of GitOps tools like Argo CD is automated reconciliation. By enabling an automated sync policy with the 'self-heal' option, Argo CD will continuously monitor for drift and automatically revert any manual changes (like the
kubectl set imagecommand) to match the configuration defined in the Git repository, thus enforcing Git as the single source of truth. - 6
A financial services company is adopting cloud native practices and needs to ensure that all container images deployed to their production Kubernetes cluster are from a trusted, internal registry and have been scanned for critical vulnerabilities. Which combination of CNCF projects is best suited to enforce this policy at the time of deployment?
Show answer details
Correct answer: B
Harbor is a CNCF graduated project that provides a private container registry with integrated vulnerability scanning (like Trivy or Clair). Open Policy Agent (OPA) can be used as a Kubernetes admission controller to enforce policies, such as rejecting pods that attempt to use images from untrusted registries or images with known critical vulnerabilities. This combination directly addresses the requirements.
- 7
A DevOps team is managing a microservices application where different services are updated independently. They observe that a new version of the 'user-profile' service is causing intermittent failures in the 'order-processing' service. To improve debugging, they need to trace a single user request as it flows through multiple services. Which CNCF-graduated project is specifically designed to address this cross-service tracing requirement?
Show answer details
Correct answer: C
Jaeger is a CNCF-graduated project for distributed tracing. It allows developers to monitor and troubleshoot transactions in complex distributed systems, like microservices. It visualizes the path of a request as it travels through different services, which is exactly what the team needs to debug the intermittent failures. Prometheus is for metrics, and Fluentd is for logging.
- 8
A platform team is implementing GitOps using Flux. They have structured their Git repository with a
clusters/directory containing configurations fordevandprodclusters, and anapps/directory with base manifests for each application. What is the primary GitOps mechanism Flux uses to apply these manifests to the correct clusters and keep them synchronized?Show answer details
Correct answer: C
The core principle of pull-based GitOps, as implemented by tools like Flux and Argo CD, is an in-cluster operator (or agent). This operator periodically pulls the state of the Git repository and compares it to the live state of the Kubernetes cluster. If there's a difference (drift), the operator takes action to make the cluster state match the 'source of truth' in Git. This is known as reconciliation.
- 9
Which of the following are key principles of a cloud native architecture according to the CNCF? (Select TWO)
Show answer details
Correct answer: A, C
- 10
True or False: In Kubernetes, a Service of type
ClusterIPis accessible from outside the cluster by default.Show answer details
Correct answer: B
A Service of type
ClusterIPexposes the Service on a cluster-internal IP. This makes the Service reachable only from within the cluster. To expose a Service to the outside world, you must use other Service types likeNodePortorLoadBalancer, or an Ingress resource.
