Hitesh Sahu
Hitesh SahuHitesh Sahu
  1. Home
  2. ›
  3. posts
  4. ›
  5. …

  6. ›
  7. 11 1 KCNA Mock Exam 1

Loading ⏳
Fetching content, this won’t take long…


💡 Did you know?

🦈 Sharks existed before trees 🌳.

🍪 This website uses cookies

No personal data is stored on our servers however third party tools Google Analytics cookies to measure traffic and improve your website experience. Learn more

Loading ⏳
Fetching content, this won’t take long…


💡 Did you know?

🤯 Your stomach gets a new lining every 3–4 days.
kubernetes

    AI-AgenticAI

    AI-DeepLearning

    AI-GenAI

    AI-Infrastructure

    AI-Machine-Learning

    AI-Math

    AWS

    Azure

    Hobbies

    kubernetes
    • Kubernetes: Control Loops, Scheduling, and GPUs

    • Image Internals: From OCI Layers to a Running Container

    • Container Internals: What a Container Really Is

    • Kubernetes Pod Internals: What a Pod Really Is

    • Kubernetes API Server Internals

    • Kubernetes Resource Allocation: Requests, Limits, QoS, and Quotas

    • etcd Architecture Explained

    • Kubernetes Scheduler Internals

    • Kubelet Internals: The Node Agent That Runs Everything

    • Kubernetes Informers & Controllers Explained

    • Kubernetes Networking: Pods, Services, Ingress, and CNI

    • Kubernetes Storage: PV, PVC, StorageClass, and CSI

    • Helm: Kubernetes Package Manager

    • Cloud Native Observability: Prometheus, Grafana, OpenTelemetry, and Tracing

    • GPU Scheduling in Kubernetes: Device Plugins, GPU Operator & MIG

    • NVIDIA Network Operator: InfiniBand, SR-IOV, RDMA, and Multus

    • Dynamic Resource Allocation: The Future of GPU Scheduling in Kubernetes

    • Kubernetes Performance at Scale

    • Optimizing AI Inference at Scale: The Full Stack

    • Kueue: Kubernetes-Native Job Queuing and Quota Management

    • Multi-Node Distributed Training on Kubernetes

    • Kubernetes Topology Manager: NUMA-Aware GPU Scheduling

    • NVIDIA NIM: Optimized Inference Microservices on Kubernetes

    • GPU Autoscaling on Kubernetes: KEDA, HPA, and Cluster Autoscaler

    • Fine-Tuning LLMs: LoRA, QLoRA, PEFT, and NeMo on Kubernetes

    • Flash Attention: Fast, Memory-Efficient Attention for LLMs

    • Kubernetes and Cloud Native Certification Path

    • KCNA Mock Exam — Set 1

    • KCNA Mock Exam — Set 2

    • KCSA Mock Exam — Set 1

    • KCSA Mock Exam — Set 2

    • kubernetes Index


    Management

    Programming

    Terraform

    Z_Appendix

    0-root

Cover Image for KCNA Mock Exam — Set 1
kubernetes

KCNA Mock Exam — Set 1

A 60-question practice exam for the Kubernetes and Cloud Native Associate (KCNA) certification, weighted to the official exam domains — Kubernetes Fundamentals, Container Orchestration, Cloud Native Application Delivery, and Cloud Native Architecture.

Kubernetes
KCNA
CNCF
Certification
Mock Exam
Cloud Native
← Previous

KCNA Mock Exam — Set 2

Next →

Kubelet Internals: The Node Agent That Runs Everything

KCNA Mock Exam - Set 1

Total Questions: 60 Time Limit: 90 minutes Passing Score: 75% (45 correct answers)

Exam Domain Distribution

Questions are distributed according to official KCNA exam weights:

  • Kubernetes Fundamentals (44%): Questions 1-27
  • Container Orchestration (28%): Questions 28-44
  • Cloud Native Application Delivery (16%): Questions 45-53
  • Cloud Native Architecture (12%): Questions 54-60

Section 1: Kubernetes Fundamentals (Questions 1-27)

Question 1

You need to temporarily prevent new pods from being scheduled on a node for maintenance. Which command should you use?

A. kubectl taint nodes node1 maintenance=true:NoSchedule
B. kubectl cordon node1
C. kubectl drain node1
D. kubectl delete node node1

Answer: B

kubectl cordon marks a node as unschedulable, preventing new pods from being scheduled while existing pods continue running. This is ideal for temporary maintenance. Option A (taint) is more complex and requires pod tolerations. Option C (drain) would evict existing pods. Option D would remove the node entirely.

Question 2

What is the primary purpose of an init container in Kubernetes?

A. To run alongside the main container throughout the pod's lifecycle
B. To perform setup tasks that must complete before the main container starts
C. To monitor the health of the main container
D. To handle network traffic for the main container

Answer: B

Init containers run to completion before the main application containers start. They're used for setup tasks like waiting for services, populating volumes, or running initialization scripts. They don't run alongside the main container (that's a sidecar).

Question 3

Which kubectl command creates a deployment named "web-app" with the nginx image?

A. kubectl run web-app --image=nginx
B. kubectl create deployment web-app --image=nginx
C. kubectl deploy web-app --image=nginx
D. kubectl apply deployment web-app --image=nginx

Answer: B

kubectl create deployment creates a deployment resource. Option A creates a pod, not a deployment. Options C and D use non-existent commands.

Question 4

What is the difference between kubectl create and kubectl run?

A. kubectl create creates any resource type; kubectl run creates only pods
B. kubectl create is deprecated; kubectl run is the new standard
C. They are identical commands with different syntax
D. kubectl create is for YAML files only; kubectl run is for command-line creation

Answer: A

kubectl create is a general command for creating any Kubernetes resource from specifications. kubectl run was historically used for creating deployments but now primarily creates pods. Neither is deprecated.

Question 5

Which Pod Security Standard provides the most restrictive security policies?

A. Privileged
B. Baseline
C. Restricted
D. Default

Answer: C

The three Pod Security Standards are:

  • Privileged: Unrestricted (least secure)
  • Baseline: Minimal restrictions
  • Restricted: Most restrictive, follows pod hardening best practices

Question 6

You have a database application that requires persistent storage and stable network identity. Which workload type should you use?

A. Deployment
B. StatefulSet
C. DaemonSet
D. Job

Answer: B

Databases require:

  • Stable network identity (predictable pod names)
  • Persistent storage that follows the pod
  • Ordered deployment and scaling

StatefulSets provide all of these. Deployments are for stateless applications.

Question 7

What happens to existing pods on a node when you run kubectl cordon node1?

A. All pods are immediately evicted
B. Existing pods continue running; no new pods can be scheduled
C. Pods are gracefully terminated
D. The node is removed from the cluster

Answer: B

kubectl cordon only affects scheduling of new pods. Existing pods remain running. To evict existing pods, you would use kubectl drain.

Question 8

Which command is used to view logs from a specific container in a pod?

A. kubectl describe pod <pod-name>
B. kubectl get logs <pod-name>
C. kubectl logs <pod-name>
D. kubectl inspect <pod-name>

Answer: C

kubectl logs retrieves container logs. Add -c <container-name> for multi-container pods. kubectl describe shows events and metadata, not logs.

Question 9

What is the purpose of a namespace in Kubernetes?

A. To provide network isolation between pods
B. To organize and isolate resources within a cluster
C. To define pod security policies
D. To manage container images

Answer: B

Namespaces provide a way to divide cluster resources between multiple users or projects. They provide scope for names and can have resource quotas. They don't provide network isolation by default (Network Policies do that).

Question 10

Which component is responsible for scheduling pods to nodes in a Kubernetes cluster?

A. kubelet
B. kube-proxy
C. kube-scheduler
D. controller-manager

Answer: C

The kube-scheduler watches for newly created pods and assigns them to nodes based on resource requirements, constraints, and policies. kubelet runs on nodes and ensures containers are running. kube-proxy handles network rules.

Question 11

What kubectl command can you use to modify a deployment's replica count?

A. kubectl edit deployment <name>
B. kubectl patch deployment <name> -p '{"spec":{"replicas":5}}'
C. kubectl scale deployment <name> --replicas=5
D. All of the above

Answer: D

All three methods can modify a deployment's replica count:

  • kubectl edit opens the resource in an editor
  • kubectl patch applies partial changes
  • kubectl scale is specifically designed for scaling

Question 12

Which kubectl command creates a pod that runs only once and terminates?

A. kubectl create pod <name> --image=<image>
B. kubectl run <name> --image=<image> --restart=Never
C. kubectl apply -f pod.yaml --once
D. kubectl execute <name> --image=<image>

Answer: B

The --restart=Never flag creates a pod that won't be restarted after completion, running only once. Default restart policy is "Always".

Question 13

What is the default restart policy for pods in Kubernetes?

A. Never
B. OnFailure
C. Always
D. RestartOnError

Answer: C

The default restart policy for pods is "Always", meaning containers will be restarted regardless of exit status. Other options are "OnFailure" and "Never".

Question 14

Which resource ensures that a specific number of pod replicas are running at all times?

A. Pod
B. ReplicaSet
C. Service
D. ConfigMap

Answer: B

A ReplicaSet ensures that a specified number of pod replicas are running at any given time. Deployments manage ReplicaSets, and ReplicaSets manage pods.

Question 15

You need to update a deployment's container image. Which command should you use?

A. kubectl set image deployment/<name> <container>=<new-image>
B. kubectl update deployment/<name> --image=<new-image>
C. kubectl modify deployment/<name> image=<new-image>
D. kubectl change deployment/<name> --image=<new-image>

Answer: A

kubectl set image is the imperative command to update container images. Other commands listed don't exist in kubectl.

Question 16

What is the purpose of labels in Kubernetes?

A. To provide human-readable names for resources
B. To organize and select groups of objects
C. To define resource quotas
D. To configure network policies

Answer: B

Labels are key-value pairs attached to objects for organization and selection. Selectors use labels to identify groups of resources. They're essential for Services, Deployments, and other controllers.

Question 17

Which file format is primarily used for Kubernetes resource definitions?

A. JSON only
B. XML
C. YAML or JSON
D. TOML

Answer: C

Kubernetes accepts both YAML and JSON for resource definitions. YAML is more commonly used because it's more human-readable and supports comments.

Question 18

What is a pod in Kubernetes?

A. A single container
B. The smallest deployable unit that can contain one or more containers
C. A group of nodes
D. A storage volume

Answer: B

A pod is the smallest and simplest Kubernetes object. It can contain one or more tightly coupled containers that share storage and network resources.

Question 19

Which kubectl command displays detailed information about a specific resource?

A. kubectl get <resource> <name> -o wide
B. kubectl inspect <resource> <name>
C. kubectl describe <resource> <name>
D. kubectl info <resource> <name>

Answer: C

kubectl describe provides detailed information about a resource, including events, conditions, and relationships. kubectl get -o wide shows additional columns but less detail than describe.

Question 20

What is the purpose of a Service in Kubernetes?

A. To provide persistent storage for pods
B. To expose pods to network traffic
C. To schedule pods on nodes
D. To manage pod lifecycle

Answer: B

A Service provides stable networking for pods. It creates a stable IP address and DNS name and load balances traffic across matching pods. Services abstract pod IP addresses which change when pods are recreated.

Question 21

Which Pod Security Standard should be used for security-sensitive workloads that require maximum isolation?

A. Privileged
B. Baseline
C. Restricted
D. Enhanced

Answer: C

The Restricted Pod Security Standard is the most secure, enforcing pod hardening best practices. It prevents privilege escalation, requires running as non-root, and restricts capabilities.

Question 22

What command removes a taint from a node?

A. kubectl taint nodes <node> key:NoSchedule-
B. kubectl untaint nodes <node> key
C. kubectl remove taint <node> key
D. kubectl delete taint <node> key

Answer: A

The minus sign (-) at the end removes a taint. Format: kubectl taint nodes <node> <key>:<effect>-

Question 23

Which Kubernetes object stores non-sensitive configuration data as key-value pairs?

A. Secret
B. ConfigMap
C. Volume
D. PersistentVolume

Answer: B

ConfigMaps store non-sensitive configuration data as key-value pairs or files. Secrets are for sensitive data. Both can be consumed as environment variables or mounted as files.

Question 24

What is the primary role of kubelet?

A. Schedule pods to nodes
B. Manage the API server
C. Ensure containers are running on a node
D. Route network traffic

Answer: C

kubelet is the node agent that ensures containers are running as specified in pod specifications. It communicates with the API server and manages container runtime.

Question 25

Which command displays all pods in all namespaces?

A. kubectl get pods
B. kubectl get pods --all
C. kubectl get pods --all-namespaces
D. kubectl get pods -n *

Answer: C

The --all-namespaces flag (or -A) shows resources across all namespaces. Without it, kubectl only shows resources in the current namespace.

Question 26

What happens when a pod's liveness probe fails?

A. The pod is marked as unhealthy but continues running
B. The container is restarted
C. The pod is deleted
D. Nothing, it's just a warning

Answer: B

When a liveness probe fails repeatedly, Kubernetes restarts the container. Readiness probes stop traffic but don't restart. Startup probes protect slow-starting containers.

Question 27

Which kubectl command can be used to execute a command inside a running container?

A. kubectl exec <pod-name> -- <command>
B. kubectl run <pod-name> <command>
C. kubectl execute <pod-name> <command>
D. kubectl ssh <pod-name> <command>

Answer: A

kubectl exec executes commands in a running container. The -- separates kubectl arguments from the command to execute. Add -it for interactive terminal.


Section 2: Container Orchestration (Questions 28-44)

Question 28

What is the purpose of a DaemonSet?

A. To run a copy of a pod on all (or some) nodes in the cluster
B. To ensure a specified number of pod replicas are running
C. To run pods that perform batch jobs
D. To manage stateful applications

Answer: A

DaemonSets ensure that a pod runs on every node (or selected nodes using node selectors). Common use cases include log collectors, monitoring agents, and storage daemons.

Question 29

Which Container Runtime Interface (CRI) compliant runtime can be used with Kubernetes?

A. containerd
B. CRI-O
C. Docker Engine (via dockershim)
D. Both A and B

Answer: D

Both containerd and CRI-O implement the Container Runtime Interface and can be used with Kubernetes. Docker Engine requires dockershim (deprecated) or containerd.

Question 30

What type of storage is best suited for a StatefulSet running a database?

A. emptyDir
B. PersistentVolume with ReadWriteOnce access mode
C. hostPath
D. ConfigMap

Answer: B

StatefulSets require persistent storage that survives pod rescheduling. PersistentVolumes with ReadWriteOnce provide dedicated storage per pod. emptyDir is ephemeral and deleted when pods are removed.

Question 31

What is the primary difference between a Deployment and a StatefulSet?

A. Deployments are for stateless apps; StatefulSets provide stable network identity and persistent storage
B. StatefulSets cannot be scaled
C. Deployments require more resources
D. StatefulSets do not support rolling updates

Answer: A

Key differences:

  • Deployments: stateless, interchangeable pods, shared storage
  • StatefulSets: stateful, unique pod identities (pod-0, pod-1), dedicated persistent volumes, ordered operations

Question 32

Which network policy type controls incoming traffic to pods?

A. Egress
B. Ingress
C. Both A and B
D. Route

Answer: B

Network Policies have two types:

  • Ingress: Controls incoming traffic TO pods
  • Egress: Controls outgoing traffic FROM pods

A policy can define both.

Question 33

What is the purpose of a sidecar container?

A. To replace the main container when it fails
B. To extend or enhance the functionality of the main container
C. To schedule the main container
D. To monitor node health

Answer: B

Sidecar containers run alongside the main container in the same pod, sharing network and storage. Common uses: logging, monitoring, proxies, service mesh. They enhance without replacing the main container.

Question 34

Which volume type is suitable for sharing files between containers in the same pod?

A. PersistentVolume
B. hostPath
C. emptyDir
D. nfs

Answer: C

emptyDir is a temporary volume that exists as long as the pod runs. It's shared between all containers in the pod. When the pod is removed, the emptyDir is deleted. Perfect for scratch space or sharing files between containers.

Question 35

What does HPA (Horizontal Pod Autoscaler) scale based on?

A. Node capacity only
B. CPU utilization, memory, or custom metrics
C. Network traffic only
D. Storage usage

Answer: B

HPA can scale based on:

  • CPU utilization
  • Memory utilization
  • Custom metrics (from applications or external systems)
  • Multiple metrics simultaneously

Question 36

Can HPA be used with a DaemonSet?

A. Yes, it's recommended
B. No, because DaemonSets run one pod per node by design
C. Yes, but only for CPU metrics
D. No, DaemonSets don't support scaling

Answer: B

DaemonSets maintain one pod per node (or selected nodes). Horizontal scaling doesn't make sense for DaemonSets since you can't have multiple pods of the same DaemonSet on one node.

Question 37

What scheduler task is NOT a primary responsibility of the Kubernetes scheduler?

A. Selecting which node a pod should run on
B. Monitoring pod health
C. Considering resource requirements when placing pods
D. Respecting node taints and pod tolerations

Answer: B

The scheduler assigns pods to nodes. It doesn't monitor pod health (kubelet does that via probes). Scheduler responsibilities:

  • Select nodes for pods
  • Consider resource requirements
  • Respect taints, tolerations, and affinity rules

Question 38

Which resource is used to store sensitive information like passwords?

A. ConfigMap
B. Secret
C. Volume
D. Environment variables only

Answer: B

Secrets are designed to store sensitive information like passwords, OAuth tokens, and SSH keys. While not encrypted by default, they're more secure than ConfigMaps and can be encrypted at rest with proper configuration.

Question 39

How are Secrets stored in Kubernetes by default?

A. Encrypted at rest automatically
B. Base64 encoded (not encrypted)
C. Plain text
D. Hashed with SHA-256

Answer: B

By default, Secrets are only base64 encoded, NOT encrypted. Base64 is encoding, not encryption—anyone with access to etcd can decode them. Enable encryption at rest in API server configuration for true security.

Question 40

You want to ensure that a specific pod only runs on nodes with GPU hardware. What should you use?

A. Pod affinity
B. Node selector or node affinity
C. DaemonSet
D. Taints only

Answer: B

To target specific hardware:

  • Node selectors: Simple label matching (e.g., gpu=true)
  • Node affinity: More expressive rules
  • Taints/tolerations: Also work but are typically for repelling pods

Question 41

What is the correct taint effect to prevent new pods from scheduling but allow existing pods to continue running?

A. NoExecute
B. NoSchedule
C. PreferNoSchedule
D. PreventSchedule

Answer: B

Taint effects:

  • NoSchedule: Prevents new pods from scheduling (existing pods stay)
  • PreferNoSchedule: Soft version, tries to avoid scheduling
  • NoExecute: Evicts existing pods and prevents new ones

Question 42

Which of the following can trigger a pod eviction?

A. Node running out of resources
B. Taint with NoExecute effect
C. kubectl drain command
D. All of the above

Answer: D

Pods can be evicted by:

  • Node resource pressure (out of memory, disk)
  • Taints with NoExecute effect
  • kubectl drain command
  • API-initiated eviction

Question 43

What is the primary purpose of a Service Account in Kubernetes?

A. To allow users to access the cluster
B. To provide an identity for pods to interact with the Kubernetes API
C. To manage node authentication
D. To store user passwords

Answer: B

Service Accounts provide an identity for processes running in pods. They allow pods to authenticate with the API server and access cluster resources. Each namespace has a default service account.

Question 44

Which workload type is best for running a web application that sends requests to other microservices?

A. StatefulSet
B. DaemonSet
C. Deployment
D. Job

Answer: C

Web applications that proxy or send traffic are stateless. They don't need persistent storage or stable identity. Deployments are perfect for stateless applications that can be scaled horizontally.


Section 3: Cloud Native Application Delivery (Questions 45-53)

Question 45

What is the primary purpose of ArgoCD?

A. Container image building
B. GitOps continuous delivery for Kubernetes
C. Log aggregation
D. Network routing

Answer: B

ArgoCD is a declarative GitOps continuous delivery tool. It monitors Git repositories and automatically synchronizes the desired state to Kubernetes clusters. Perfect for multi-cluster deployments and automated delivery.

Question 46

When should you use Helm?

A. To package and deploy Kubernetes applications using templates
B. To monitor cluster performance
C. To manage container images
D. To configure network policies

Answer: A

Helm is a package manager for Kubernetes. It uses templates (charts) to define, install, and upgrade Kubernetes applications. Charts can be versioned, shared, and customized with values files.

Question 47

What is a Helm chart?

A. A performance monitoring tool
B. A package of Kubernetes resources
C. A network topology diagram
D. A container image registry

Answer: B

A Helm chart is a collection of files that describe related Kubernetes resources. It includes templates, default values, and metadata. Charts can be shared via repositories.

Question 48

What is the main advantage of GitOps?

A. Faster container startup times
B. Using Git as the single source of truth for infrastructure and applications
C. Reduced storage costs
D. Improved network performance

Answer: B

GitOps core principles:

  • Git is the source of truth
  • Declarative configuration
  • Automated synchronization
  • Version control for infrastructure
  • Audit trail via Git history

Question 49

Which deployment strategy involves running two identical production environments (old and new)?

A. Rolling update
B. Canary deployment
C. Blue-green deployment
D. Recreate

Answer: C

Blue-green deployment maintains two identical environments:

  • Blue: Current production
  • Green: New version

Traffic switches completely from blue to green once validated. Enables instant rollback.

Question 50

What is the purpose of an Ingress controller?

A. To manage container lifecycle
B. To provide HTTP/HTTPS routing to services
C. To schedule pods on nodes
D. To store application secrets

Answer: B

Ingress controllers implement Ingress resources, providing:

  • HTTP/HTTPS routing
  • Load balancing
  • SSL/TLS termination
  • Name-based virtual hosting

Question 51

What advantage does Gateway API have over traditional Ingress?

A. Faster performance
B. Lower resource usage
C. Role-oriented design, multi-protocol support, and better extensibility
D. Simpler configuration

Answer: C

Gateway API advantages over Ingress:

  • Role-oriented: Separate resources for different roles
  • Multi-protocol: HTTP, HTTPS, TCP, UDP, gRPC
  • Extensible: Standardized extension points
  • Cross-namespace routing
  • Better traffic management (canary, A/B testing)

Question 52

Which tool would you use to deploy applications to multiple Kubernetes clusters from a Git repository?

A. Helm
B. ArgoCD
C. kubectl
D. Docker

Answer: B

ArgoCD excels at multi-cluster management with Git as the source of truth. It can deploy to multiple clusters from a single Git repository, monitor sync status, and auto-heal configuration drift.

Question 53

What is a key benefit of using declarative configuration for Kubernetes resources?

A. Faster execution
B. Desired state can be version controlled and automatically reconciled
C. Requires less storage
D. Works without an API server

Answer: B

Declarative configuration (YAML/JSON) describes the desired state. Kubernetes controllers automatically reconcile actual state to match desired state. Benefits: version control, repeatability, auditability.


Section 4: Cloud Native Architecture (Questions 54-60)

Question 54

Which CNCF project is used for collecting metrics and monitoring Kubernetes clusters?

A. Fluentd
B. Prometheus
C. Envoy
D. CoreDNS

Answer: B

Prometheus is the CNCF standard for metrics collection and monitoring. It collects time-series data, provides a powerful query language (PromQL), and integrates with Grafana for visualization.

Question 55

What is the purpose of distributed tracing?

A. To track requests as they flow through microservices
B. To monitor disk usage
C. To manage network routing
D. To schedule container workloads

Answer: A

Distributed tracing tracks requests across multiple services, showing:

  • Request path through services
  • Latency at each hop
  • Errors and bottlenecks
  • Service dependencies

Tools: Jaeger, Zipkin

Question 56

What are "spans" in the context of distributed tracing?

A. Network segments
B. Individual units of work in a distributed system
C. Storage volumes
D. Pod replicas

Answer: B

In distributed tracing:

  • Trace: Complete journey of a request
  • Span: Individual operation within a trace (e.g., database query, HTTP call)

Spans have start time, duration, and metadata.

Question 57

Which of the following is a core principle of cloud-native architecture?

A. Monolithic application design
B. Manual scaling and deployment
C. Microservices, containers, and dynamic orchestration
D. Single point of failure for simplicity

Answer: C

Cloud-native principles:

  • Microservices architecture
  • Containerization
  • Dynamic orchestration (Kubernetes)
  • Automation and CI/CD
  • Resilience and observability
  • DevOps culture

Question 58

What is the role of the CNCF (Cloud Native Computing Foundation)?

A. To sell cloud computing services
B. To provide a vendor-neutral home for open-source cloud-native projects
C. To compete with Kubernetes
D. To develop proprietary cloud solutions

Answer: B

CNCF (Cloud Native Computing Foundation) hosts and nurtures cloud-native open-source projects like Kubernetes, Prometheus, Envoy, and many others. It's vendor-neutral and part of the Linux Foundation.

Question 59

Which image pull policy instructs Kubernetes to always pull the container image from the registry?

A. IfNotPresent
B. Never
C. Always
D. OnUpdate

Answer: C

Image pull policies:

  • Always: Pull image every time (latest tags)
  • IfNotPresent: Pull only if not cached locally (default for specific tags)
  • Never: Never pull, must exist locally

Question 60

You have an application that requires a database with persistent storage and consistent network identity. Which statement is correct?

A. Use a Deployment because it's more flexible
B. Use a StatefulSet because databases need stable identity and persistent volumes
C. Use a DaemonSet to ensure the database runs on every node
D. Use a Job because databases complete their work and exit

Answer: B

Databases require:

  • Persistent storage (data survives restarts)
  • Stable network identity (for replication, clustering)
  • Ordered scaling (primary before replicas)

StatefulSets provide all of these guarantees.

Hitesh Sahu
Written by Hitesh Sahu, a passionate developer and blogger.

Wed Jul 29 2026

Share This on

← Previous

KCNA Mock Exam — Set 2

Next →

Kubelet Internals: The Node Agent That Runs Everything

kubernetes/11-1-KCNA-Mock-Exam-1
Let's work together
+49 176-2019-2523
hiteshkrsahu@gmail.com
WhatsApp
Skype
Munich 🥨, Germany 🇩🇪, EU
Playstore
Hitesh Sahu's apps on Google Play Store
Need Help?
Let's Connect
Navigation
  Home/About
  Skills
  Work/Projects
  Lab/Experiments
  Contribution
  Awards
  Art/Sketches
  Thoughts
  Contact
Links
  Sitemap
  Legal Notice
  Privacy Policy

Made with

NextJS logo

NextJS by

hitesh Sahu

| © 2026 All rights reserved.