CKA Sample Questions & Answers
Diagnosing cluster problems and monitoring resources is the single biggest topic, alongside RBAC and cluster installation, pod connectivity and network policies, application deployment with autoscaling, and storage classes with persistent volumes.
Launch the full CKA simulator →Showing 10 of 20 free samples.
- Question 1IntermediateSelect 2
Workloads and Scheduling · Configure Pod admission and scheduling (limits, node affinity, etc.)
An administrator needs to deploy a monitoring agent as a DaemonSet to all nodes in the cluster, but the control plane nodes must be excluded. The control plane nodes are labeled
node-role.kubernetes.io/control-planeand tainted withnode-role.kubernetes.io/control-plane:NoSchedule. Which TWO of the following statements about excluding the control plane nodes are correct? (Select TWO)Show answer & explanation
Correct answers: A, D
The DaemonSet controller adds only a fixed set of tolerations to its Pods:
node.kubernetes.io/not-readyandnode.kubernetes.io/unreachable(NoExecute), anddisk-pressure,memory-pressure,pid-pressure,unschedulableand, for hostNetwork Pods,network-unavailable(NoSchedule). The control-plane taint is not among them, so the existingnode-role.kubernetes.io/control-plane:NoScheduletaint already keeps DaemonSet Pods off the control plane nodes; the documentation's example adds an explicit control-plane toleration only to make a DaemonSet run there. To make the exclusion explicit (for example, in case a broad toleration is added later), add required node affinity withkey: node-role.kubernetes.io/control-planeandoperator: DoesNotExist; the DaemonSet controller creates Pods only on nodes that match the Pod template's node affinity. Adding the toleration would do the opposite, DaemonSets have noreplicasfield, and taints are not ignored for DaemonSet Pods, so no anti-affinity rule against kube-apiserver Pods is needed.The DaemonSet controller adds only a fixed set of tolerations to its Pods:
node.kubernetes.io/not-readyandnode.kubernetes.io/unreachable(NoExecute), anddisk-pressure,memory-pressure,pid-pressure,unschedulableand, for hostNetwork Pods,network-unavailable(NoSchedule). The control-plane taint is not among them, so the existingnode-role.kubernetes.io/control-plane:NoScheduletaint already keeps DaemonSet Pods off the control plane nodes; the documentation's example adds an explicit control-plane toleration only to make a DaemonSet run there. To make the exclusion explicit (for example, in case a broad toleration is added later), add required node affinity withkey: node-role.kubernetes.io/control-planeandoperator: DoesNotExist; the DaemonSet controller creates Pods only on nodes that match the Pod template's node affinity. Adding the toleration would do the opposite, DaemonSets have noreplicasfield, and taints are not ignored for DaemonSet Pods, so no anti-affinity rule against kube-apiserver Pods is needed. - Question 2Beginner
Cluster Architecture, Installation and Configuration · Manage role based access control (RBAC)
You are auditing RBAC permissions and need to quickly verify if a specific service account,
app-readerin thestagingnamespace, has permission togetpods in theproductionnamespace. Which command provides a clear 'yes' or 'no' answer to this question?Show answer & explanation
Correct answer: B
The
kubectl auth can-isubcommand is specifically designed for this purpose. It allows you to impersonate a user, group, or service account (using the--asflag) and check if they have permission to perform a specific action on a resource. It returns a simple 'yes' or 'no', making it the most direct and efficient way to answer the question. - Question 3Intermediate
Services & Networking · Use ClusterIP, NodePort, LoadBalancer service types and endpoints
A new cluster administrator is trying to understand the flow of traffic for a service exposed via NodePort. They observe that a request sent to
node-ip:node-porton any node in the cluster correctly routes to a pod, even if that pod is not running on the node that received the request.Which component is responsible for this routing behavior across the cluster?
graph TD Client -->|"Request to Node2_IP:NodePort"| Rules2 subgraph Node2 Rules2["Service forwarding rules on Node2"] end subgraph Node1 TargetPod[Target Pod] end Rules2 -->|"DNAT to the Pod IP, delivered over the Pod network"| TargetPodShow answer & explanation
Correct answer: D
kube-proxy runs on every node and watches Services and EndpointSlices. For a NodePort Service it programs packet-forwarding rules on every node, so every node accepts traffic on the node port. On Linux these are iptables rules by default, or nftables; IPVS mode is deprecated in v1.35. The kernel then DNATs the packet to one of the ready backend Pod IPs, which may be on another node, and the Pod network set up by the CNI plugin delivers it there. kube-proxy does not relay the packets itself. CoreDNS only resolves names. The CNI plugin provides Pod-to-Pod connectivity but not the Service-to-Pod mapping. An Ingress controller handles HTTP routing for Ingress resources, not NodePort traffic.
- Question 4Beginner
Troubleshooting · Monitor cluster and application resource usage
A critical application is experiencing performance degradation. You suspect a 'noisy neighbor' pod is consuming excessive CPU resources on a worker node. Which
kubectlcommand would you use to identify the pods consuming the most CPU on all nodes in the cluster?Show answer & explanation
Correct answer: A
The
kubectl top podscommand displays CPU and memory usage for pods. The-Aflag (or--all-namespaces) ensures you see pods from all namespaces, and--sort-by=cpuorders the output to show the highest CPU consumers first, making it easy to identify the culprit. This command requires the Metrics Server to be installed in the cluster. - Question 5Beginner
Cluster Architecture, Installation and Configuration · Prepare underlying infrastructure for installing a Kubernetes cluster
True or False: When using
kubeadmwith the default kubelet configuration, swap should be disabled on all nodes (both control plane and worker) before runningkubeadm initorkubeadm join.Show answer & explanation
Correct answer: A
True. The v1.35 install guide says that 'the default behavior of a kubelet is to fail to start if swap memory is detected on a node', so swap must be either disabled or explicitly tolerated. With the default configuration (
failSwapOn: true), disable it on every node withsudo swapoff -a. Then remove the swap entries from/etc/fstab(or disable the systemd swap units) so it stays off after a reboot. Tolerating swap is an explicit opt-in: setfailSwapOn: falseand, if workloads should use swap, aswapBehaviorother than the defaultNoSwap(swap support is GA since v1.34). kubeadm's own preflight check only warns about swap; it is the kubelet that refuses to start. - Question 6Intermediate
Storage · Manage persistent volumes and persistent volume claims
You need to provision a PersistentVolume that sources its storage directly from a directory,
/data/mysql-pv, on a specific worker node,node-03. This volume should be 5Gi in size and have aReadWriteOnceaccess mode. Which of the following YAML snippets correctly defines this PersistentVolume?Show answer & explanation
Correct answer: B
This is the correct and modern way to define a node-specific local volume. It uses the
localvolume type and anodeAffinitysection to ensure that any pod claiming this volume will be scheduled ontonode-03. UsinghostPathfor a PV is discouraged as it doesn't have this scheduling awareness, which can lead to pods being scheduled on the wrong node and failing to mount the volume. - Question 7Advanced
Cluster Architecture, Installation and Configuration · Manage the lifecycle of Kubernetes clusters
You have been given a backup file of an etcd database located at
/tmp/etcd-backup.db. The cluster's etcd is running as a static pod. You need to restore the cluster state from this backup file. Which command should you run to perform the restore?Show answer & explanation
Correct answer: A
etcdutlworks directly on etcd data files, and it is the restore tool in the v1.35 docs.etcdutl --data-dir snapshot restoreunpacks the snapshot into a new data directory, which the command creates.etcdctl snapshot restorewas deprecated in etcd v3.5 and removed in v3.6, and kubeadm v1.35 deploys etcd 3.6.6. Stop all API server instances before restoring. Then point the etcd static Pod at the new directory by changing theetcd-datahostPathin/etc/kubernetes/manifests/etcd.yaml. Let the kubelet recreate the Pod (or restart the kubelet), and restart the API servers and the other control plane components. Running the restore inside the live etcd Pod does not work, because the backup file is on the host and the member is in use. A snapshot file cannot simply be moved intomember/snap/db, and kubeadm has no--restore-fromoption. - Question 8Intermediate
Services & Networking · Use the Gateway API to manage Ingress traffic
A team is transitioning from a traditional Ingress resource to the newer Gateway API for more flexible traffic management. They need to configure a simple routing rule: traffic to
store.example.com/should be directed to a service namedfrontend-svc. Which combination of Gateway API resources is required to accomplish this?Show answer & explanation
Correct answer: C
The Gateway API separates concerns into different resources. The
Gatewayresource is typically managed by the cluster administrator and defines the listener (e.g., port 443, hostname). TheHTTPRouteresource is managed by application developers and attaches to a Gateway, defining specific routing rules like matching a path (/) and forwarding traffic to a backend service (frontend-svc). - Question 9BeginnerSelect 3
Troubleshooting · Troubleshoot clusters and nodes
A pod is failing to start with the status
ImagePullBackOff. Which of the following are potential root causes for this error? (Select THREE)Show answer & explanation
Correct answers: B, C, D
ImagePullBackOffmeans that a container could not start because its image could not be pulled; Kubernetes keeps retrying with an increasing back-off delay capped at 300 seconds. The Kubernetes docs name an invalid image name and pulling from a private registry without animagePullSecretas typical reasons. A misspelled image name or tag (the registry has no such image), a node that cannot reach the registry over the network (for example a firewall, proxy or DNS problem), and a missing or wrongimagePullSecretfor a private registry (authentication fails) therefore all lead to it. A failing liveness probe restarts a container that is already running, which shows up as restarts orCrashLoopBackOff, not as a pull error. A CPU request that no node can satisfy keeps the PodPendingwith aFailedSchedulingevent, before any image is pulled.ImagePullBackOffmeans that a container could not start because its image could not be pulled; Kubernetes keeps retrying with an increasing back-off delay capped at 300 seconds. The Kubernetes docs name an invalid image name and pulling from a private registry without animagePullSecretas typical reasons. A misspelled image name or tag (the registry has no such image), a node that cannot reach the registry over the network (for example a firewall, proxy or DNS problem), and a missing or wrongimagePullSecretfor a private registry (authentication fails) therefore all lead to it. A failing liveness probe restarts a container that is already running, which shows up as restarts orCrashLoopBackOff, not as a pull error. A CPU request that no node can satisfy keeps the PodPendingwith aFailedSchedulingevent, before any image is pulled.ImagePullBackOffmeans that a container could not start because its image could not be pulled; Kubernetes keeps retrying with an increasing back-off delay capped at 300 seconds. The Kubernetes docs name an invalid image name and pulling from a private registry without animagePullSecretas typical reasons. A misspelled image name or tag (the registry has no such image), a node that cannot reach the registry over the network (for example a firewall, proxy or DNS problem), and a missing or wrongimagePullSecretfor a private registry (authentication fails) therefore all lead to it. A failing liveness probe restarts a container that is already running, which shows up as restarts orCrashLoopBackOff, not as a pull error. A CPU request that no node can satisfy keeps the PodPendingwith aFailedSchedulingevent, before any image is pulled. - Question 10Intermediate
Cluster Architecture, Installation and Configuration · Manage role based access control (RBAC)
You are deploying a custom controller to your cluster that requires permission to watch Deployments and update Pods across all namespaces. Which combination of RBAC objects is most appropriate to grant these permissions?
Show answer & explanation
Correct answer: B
A
ClusterRoleis needed because the permissions (watchon Deployments,updateon Pods) must apply cluster-wide (across all namespaces). AClusterRoleBindingis then used to grant thatClusterRoleto the controller's ServiceAccount, making the permissions effective across the entire cluster. Using namespaced Roles and RoleBindings would be inefficient and difficult to manage.
Ready for the real thing?
The full CKA simulator has every exam-style question, timed mode, and instant scoring.