KCNA Sample Questions & Answers
Nearly half the exam centers on core Kubernetes building blocks: architecture, resources, and working with containers and images, ahead of orchestration, security and storage, cloud-native principles like autoscaling, observability, and shipping with GitOps and CI/CD.
Launch the full KCNA simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Cloud Native Architecture · Autoscaling
An e-commerce platform experiences high traffic during flash sales. The application backend, running as a Deployment, needs to scale automatically based on CPU utilization. Which Kubernetes resource is used to achieve this horizontal scaling?
Show answer & explanation
Correct answer: B
The Horizontal Pod Autoscaler (HPA) automatically scales the number of pods in a replication controller, deployment, replica set or stateful set based on observed CPU utilization (or with custom metrics support, on some other application-provided metrics). This is the standard Kubernetes mechanism for scaling out stateless applications based on load.
- Question 2Beginner
Kubernetes Fundamentals · Configuration Resources
A developer needs to provide an application running in a pod with a database password. To follow security best practices, this sensitive information should not be stored in the container image or in a ConfigMap. What is the appropriate Kubernetes resource for securely managing and injecting this password into the pod?
Show answer & explanation
Correct answer: A
Kubernetes Secrets are designed specifically for storing and managing sensitive information, such as passwords, OAuth tokens, and ssh keys. They can be mounted as data volumes or exposed as environment variables to a container in a Pod. While they are base64 encoded by default (not encrypted), they are the designated Kubernetes object for handling sensitive data separately from pods and ConfigMaps.
- Question 3Intermediate
Cloud Native Observability · Prometheus
A site reliability engineer (SRE) is using Prometheus to monitor a Kubernetes cluster. They want to create an alert that fires when a pod has been in a
CrashLoopBackOffstate for more than 15 minutes. To achieve this, the SRE needs to query a specific metric that tracks the state of containers. Which component is primarily responsible for exposing these container-level metrics to Prometheus?Show answer & explanation
Correct answer: C
The kubelet, which runs on every worker node, is responsible for managing the lifecycle of pods on that node. It exposes a
/metricsendpoint that provides detailed metrics about the node itself and the containers running on it, including container states, restarts, and resource usage. Prometheus is configured to scrape this endpoint on each node to collect these vital metrics for monitoring and alerting. - Question 4Intermediate
Container Orchestration · Networking
What is the primary role of a Container Network Interface (CNI) plugin in a Kubernetes cluster?
Show answer & explanation
Correct answer: D
The Container Network Interface (CNI) is a standard for writing plugins to configure network interfaces for Linux containers. In Kubernetes, the kubelet uses a CNI plugin (like Calico, Flannel, or Cilium) to handle networking tasks when a pod is created or destroyed. This includes assigning an IP address to the pod, setting up routes, and ensuring it can communicate with other pods according to the cluster's networking model.
- Question 5Beginner
Cloud Native Application Delivery · Application Delivery Fundamentals
A company wants to deploy a new feature to a small subset of users before rolling it out to everyone. This strategy allows them to test the feature's stability and gather feedback with minimal risk. Which application delivery strategy does this describe?
Show answer & explanation
Correct answer: B
A Canary Release is a deployment strategy where the new version of an application is gradually rolled out to a small subset of users. Traffic is selectively routed to the new version, allowing teams to monitor its performance and stability in a real production environment. If the new version performs well, traffic is incrementally shifted until all users are on the new version. This matches the described scenario.
- Question 6Advanced
Cloud Native Architecture · Open Standards
The Open Container Initiative (OCI) defines specifications to ensure interoperability between different container technologies. What are the two primary specifications defined by the OCI?
Show answer & explanation
Correct answer: B
The OCI's core mission is to create open industry standards around container formats and runtimes. It maintains two key specifications: 1) The Runtime Specification (runtime-spec), which defines how to run a 'filesystem bundle' as a container. 2) The Image Specification (image-spec), which defines the format of a container image. These standards allow different runtimes (like runC, containerd) to run images created by different build tools (like Docker, Buildah).
- Question 7Intermediate
Container Orchestration · Scheduling
A Kubernetes administrator needs to ensure that a monitoring agent pod runs on every single worker node in the cluster, but not on the control plane nodes. Which combination of Kubernetes objects and scheduling features should be used to achieve this?
Show answer & explanation
Correct answer: C
A DaemonSet is the correct Kubernetes resource to ensure that a copy of a pod runs on all (or some) nodes. By default, DaemonSets do not run on control plane nodes because these nodes usually have taints (e.g.,
node-role.kubernetes.io/control-plane:NoSchedule). To run on every worker but not the control plane, a standard DaemonSet is sufficient as it won't have the necessary toleration to be scheduled on the tainted control plane nodes. - Question 8Beginner
Kubernetes Fundamentals · Kubernetes Architecture
The Kubernetes component responsible for storing the cluster state and configuration is
_____.Show answer & explanation
Correct answer: D
etcd is a consistent and highly-available key-value store used as Kubernetes' backing store for all cluster data. All objects, states, and configurations of the Kubernetes cluster are stored in etcd, making it the single source of truth for the control plane.
- Question 9Intermediate
Cloud Native Observability · Cost Management
A cloud architect is designing a cost-effective solution for running batch processing jobs that are fault-tolerant and can be interrupted. The jobs run on a public cloud provider's Kubernetes service. To minimize compute costs, which cloud native practice should the architect strongly consider for the nodes running these jobs?
Show answer & explanation
Correct answer: B
Spot instances (or preemptible VMs) are unused compute capacity offered by cloud providers at a significant discount compared to on-demand prices. They can be terminated with very little notice, making them ideal for fault-tolerant, interruptible workloads like batch processing. In Kubernetes, nodes from spot instance groups are typically tainted, and the batch job pods must have the corresponding toleration to be scheduled on them.
- Question 10Advanced
Kubernetes Fundamentals · Networking Resources
CASE STUDY
A retail startup, 'ShopFast', is migrating its monolithic e-commerce application to a microservices architecture on Kubernetes. The development team has successfully containerized the 'product-catalog', 'shopping-cart', and 'payment-gateway' services.
Current Situation:
The services are deployed, but they cannot communicate with each other. The team also needs a way to expose the 'product-catalog' service to the internet securely via HTTPS on the domainapi.shopfast.comso their mobile app can fetch product data. They have deployed an NGINX Ingress controller in the cluster.Requirements:
- Enable service-to-service communication within the cluster.
- Expose the 'product-catalog' service externally at
api.shopfast.com/products. - Secure the external endpoint with a TLS certificate.
Proposed Architecture:
flowchart TD subgraph Kubernetes Cluster MobileApp -- HTTPS --> Ingress[Ingress: api.shopfast.com] Ingress -- HTTP --> ProductSvc[Service: product-catalog] ProductSvc --> ProductPods[Pods: product-catalog] CartSvc[Service: shopping-cart] --> CartPods[Pods: shopping-cart] PaymentSvc[Service: payment-gateway] --> PaymentPods[Pods: payment-gateway] CartSvc --> ProductSvc CartSvc --> PaymentSvc end MobileApp((Mobile App))Which set of Kubernetes resources is required to meet all of ShopFast's requirements?
Show answer & explanation
Correct answer: C
This combination correctly addresses all requirements:
- ClusterIP Services: Creating a Service of type ClusterIP for each microservice (
product-catalog,shopping-cart,payment-gateway) makes them discoverable and accessible to each other via DNS within the cluster. - Ingress Resource: An Ingress resource is needed to configure the Ingress controller. It will define the rule to route traffic from
api.shopfast.com/productsto theproduct-catalogService. - Secret: To secure the Ingress with HTTPS, a Kubernetes Secret of type
kubernetes.io/tlsis used to store the TLS private key and certificate, which is then referenced in the Ingress resource.
Ready for the real thing?
The full KCNA simulator has every exam-style question, timed mode, and instant scoring.