Kubernetes and Cloud Native Associate (KCNA) — Questions and Answers
Question 1: What does a `helm rollback` command do when given a release name and revision number?
- Reverts the chart source files to an earlier version
- Restores the release to the specified previous revision (Correct answer)
- Rolls back the Helm binary to a prior version
- Deletes the release and reinstalls from scratch
Correct answer: Restores the release to the specified previous revision
`helm rollback <release> <revision>` restores a Helm-managed release to a previously deployed revision stored in the release history.
Question 2: Which probe type in Kubernetes checks whether a container is ready to serve traffic?
- healthProbe
- startupProbe
- readinessProbe (Correct answer)
- livenessProbe
Correct answer: readinessProbe
A readinessProbe determines if a container is ready to accept traffic; failing Pods are removed from Service endpoints.
Question 3: Which of the following volume types is most appropriate for sharing temporary data between containers in the same pod?
- emptyDir (Correct answer)
- nfs
- PersistentVolumeClaim
- hostPath
Correct answer: emptyDir
emptyDir volumes are created when a pod starts and are shared among all containers in that pod, making them ideal for inter-container scratch space.
Question 4: In a Kubernetes cluster, where are container logs stored on the node by default?
- /tmp/container-logs/
- /var/log/pods/ (Correct answer)
- /run/containerd/logs/
- /etc/kubernetes/logs/
Correct answer: /var/log/pods/
Kubernetes stores container logs under /var/log/pods/ on each node, organized by namespace, pod name, and container name.
Question 5: A pod with `requiredDuringSchedulingIgnoredDuringExecution` node affinity cannot be scheduled if the rule is not satisfied. What happens to the pod?
- It is scheduled on any available node as a fallback
- It fails immediately with an error and is deleted
- It stays Pending until a matching node becomes available (Correct answer)
- It is rescheduled on a node with the closest matching labels
Correct answer: It stays Pending until a matching node becomes available
Hard affinity rules (`required...`) cause the pod to remain Pending indefinitely if no node satisfies the constraint.
Question 6: In Kubernetes, which scheduling concept allows you to attract Pods to specific nodes based on node labels?
- Node Affinity (Correct answer)
- Pod Disruption Budget
- Tolerations
- Taints
Correct answer: Node Affinity
Node Affinity rules allow Pods to express preferences or requirements for scheduling on nodes with certain labels.
Question 7: A Service of type ExternalName maps to what kind of resource?
- A NodePort on every cluster node
- An external IP address
- A CNAME record pointing to an external DNS name (Correct answer)
- A pod running outside the cluster
Correct answer: A CNAME record pointing to an external DNS name
ExternalName Services create a DNS CNAME record that aliases the Service name to an external hostname, enabling cluster-internal resolution of external services.
Question 8: What is the most important professional competency for KCNA certification in scheduling and scaling?
- Speed of task completion
- Deep knowledge combined with practical application skills (Correct answer)
- Memorization of all reference materials
- Ability to work alone exclusively
Correct answer: Deep knowledge combined with practical application skills
Professional competency requires both deep knowledge of the subject matter and the ability to apply that knowledge in practical situations.
Question 9: What is the role of the Kubelet in Kubernetes?
- To schedule pods on nodes.
- To manage persistent storage.
- To configure network policies.
- To ensure containers are running (Correct answer)
Correct answer: To ensure containers are running
The Kubelet is an agent that runs on each worker node in a Kubernetes cluster. Its primary role is to ensure that containers within Pods are running and healthy, communicating with the control plane to receive Pod specifications and managing the lifecycle of containers on its node.
Question 10: What is the PRIMARY purpose of obtaining KCNA certification in Kubernetes and Cloud Native Associate?
- To bypass educational requirements
- To satisfy a personal achievement goal
- To demonstrate verified competency and adherence to professional standards (Correct answer)
- To guarantee employment in the field
Correct answer: To demonstrate verified competency and adherence to professional standards
Professional certification demonstrates that an individual has met established competency standards through verified assessment. It provides assurance to employers, clients, and the public that the certified professional possesses the knowledge and skills required for competent practice.
Question 11: Which Kubernetes resource guarantees that a minimum number of Pods in a Deployment remain available during voluntary disruptions?
- LimitRange
- PriorityClass
- PodDisruptionBudget (Correct answer)
- ResourceQuota
Correct answer: PodDisruptionBudget
A PodDisruptionBudget (PDB) limits the number of Pods of a replicated application that are down simultaneously during voluntary disruptions.
Question 12: Which resource type ensures exactly one pod runs on every (or selected) node in the cluster?
- StatefulSet
- DaemonSet (Correct answer)
- ReplicaSet
- Deployment
Correct answer: DaemonSet
A DaemonSet places one pod per matching node and automatically adds pods to new nodes as they join the cluster.
Question 13: In the Backends for Frontends (BFF) pattern, what is the purpose of creating separate backends for different client types?
- To enforce consistent authentication across all clients
- To provide a single caching layer for all client types
- To aggregate metrics from all client types in one place
- To tailor API responses and logic specifically for each client's needs (Correct answer)
Correct answer: To tailor API responses and logic specifically for each client's needs
BFF creates dedicated backend services for each client type (mobile, web, etc.) allowing each to be optimized independently without compromising others.
Question 14: A Deployment is updated with a new image. Which strategy replaces Pods one at a time, ensuring no downtime?
- Recreate
- RollingUpdate (Correct answer)
- Canary
- BlueGreen
Correct answer: RollingUpdate
The RollingUpdate strategy incrementally replaces old Pods with new ones, keeping the application available during the update.
Question 15: Which Kubernetes resource allows an administrator to set default StorageClass behavior for a namespace?
- LimitRange
- NetworkPolicy
- ResourceQuota
- StorageClass with 'default' annotation (Correct answer)
Correct answer: StorageClass with 'default' annotation
Annotating a StorageClass with storageclass.kubernetes.io/is-default-class: 'true' makes it the default for PVCs that don't specify a storageClassName.
Question 16: How does the KCNA body of knowledge relate to daily professional practice?
- It provides the foundational framework that guides decision-making and standard practices (Correct answer)
- It only applies during certification exams
- It is relevant only for academic research
- It is theoretical and has limited practical application
Correct answer: It provides the foundational framework that guides decision-making and standard practices
The body of knowledge provides the foundational framework of principles, standards, and best practices that professionals use to guide their daily decision-making, ensure consistent quality, and maintain alignment with industry standards.
Question 17: What is the role of the kubelet on a Kubernetes worker node?
- Ensures containers described in PodSpecs are running and healthy (Correct answer)
- Manages iptables rules for network connectivity
- Stores cluster state in a distributed database
- Routes traffic between Services and Pods
Correct answer: Ensures containers described in PodSpecs are running and healthy
The kubelet is an agent on each node that watches for PodSpecs and ensures the containers are running as expected.
Question 18: What is the effect of adding a taint `NoSchedule` to a node?
- New Pods without a matching toleration will not be scheduled on the node (Correct answer)
- Existing Pods are evicted from the node
- All Pods on the node are restarted
- The node is removed from the cluster
Correct answer: New Pods without a matching toleration will not be scheduled on the node
A `NoSchedule` taint prevents new Pods from being scheduled on the node unless they have a matching toleration.
Question 19: What is the recommended approach for handling errors in container orchestration?
- Log errors but never handle them
- Let errors crash the application
- Suppress all error messages
- Implement structured error handling with meaningful messages (Correct answer)
Correct answer: Implement structured error handling with meaningful messages
Structured error handling with meaningful messages helps diagnose problems quickly while maintaining application stability and user experience.
Question 20: What documentation is MOST critical to maintain for safety compliance in the Kubernetes and Cloud Native Associate field?
- Client marketing preferences
- Employee vacation schedules
- Incident reports, training records, and inspection logs (Correct answer)
- Annual revenue reports
Correct answer: Incident reports, training records, and inspection logs
Incident reports, training records, and inspection logs are essential safety documentation. They demonstrate compliance with safety regulations, track training completion, and provide evidence of systematic hazard management.
Question 21: Which approach best demonstrates mastery of monitoring and logging in KCNA practice?
- Applying principles to novel situations with sound judgment (Correct answer)
- Avoiding complex scenarios
- Relying entirely on technology
- Following procedures without understanding
Correct answer: Applying principles to novel situations with sound judgment
True mastery involves understanding underlying principles well enough to apply them to new and unfamiliar situations with professional judgment.
Question 22: When using `helm upgrade` with `--atomic`, what occurs if the upgrade fails?
- Helm waits indefinitely for resources to become healthy before timing out
- Helm deletes the entire release and its history
- The failed release is left in place for manual debugging
- The upgrade is automatically rolled back to the previous successful release (Correct answer)
Correct answer: The upgrade is automatically rolled back to the previous successful release
`--atomic` combines `--wait` with automatic rollback: if any resource fails to become ready within the timeout, Helm rolls the release back to its previous revision.
Question 23: Which foundational principle is MOST important for success in the Kubernetes and Cloud Native Associate profession?
- Maintaining the minimum requirements for certification
- Maximizing financial returns on every engagement
- Commitment to continuous learning, ethical practice, and quality outcomes (Correct answer)
- Specializing in only one narrow area of practice
Correct answer: Commitment to continuous learning, ethical practice, and quality outcomes
Success in any professional field requires a commitment to continuous learning to stay current, ethical practice to maintain trust and integrity, and a focus on quality outcomes that serve stakeholders and the public interest.
Question 24: In the Sidecar pattern, what is the relationship between the sidecar container and the main application container?
- They communicate only through Kubernetes Services
- They share only storage volumes but not networking
- They run in separate Pods but the same namespace
- They share the same Pod and network namespace (Correct answer)
Correct answer: They share the same Pod and network namespace
Sidecar containers in a Pod share the same network namespace and can communicate over localhost with the main container.
Question 25: What is the difference between `kubectl drain` and `kubectl cordon`?
- cordon evicts pods; drain only prevents new pods
- drain deletes the node object; cordon just marks it unschedulable
- drain cordons the node AND evicts all pods; cordon only prevents new scheduling (Correct answer)
- They are identical; drain is an alias for cordon
Correct answer: drain cordons the node AND evicts all pods; cordon only prevents new scheduling
`drain` first cordons the node (marks it unschedulable) and then safely evicts all pods while respecting PodDisruptionBudgets.
Question 26: What problem does the Strangler Fig pattern primarily address in cloud native migrations?
- Scaling stateful workloads horizontally
- Routing traffic between multiple service versions
- Encrypting inter-service communication
- Incrementally replacing a legacy monolith with microservices (Correct answer)
Correct answer: Incrementally replacing a legacy monolith with microservices
Strangler Fig allows teams to gradually migrate a monolith by routing new features to microservices while the legacy system remains operational.
Question 27: Which Kubernetes feature enables a pod to use a raw block device rather than a filesystem-based volume?
- volumeMode: Block in the PVC and PV spec (Correct answer)
- storageType: block in the StorageClass
- hostPath with type: BlockDevice
- accessMode: RawBlock in the PVC spec
Correct answer: volumeMode: Block in the PVC and PV spec
Setting volumeMode: Block in both the PV and PVC spec instructs Kubernetes to expose the volume as a raw block device instead of mounting a filesystem.
Question 28: What is an 'ambient mesh' in the context of Istio's evolution?
- A mesh limited to HTTP/1.1 traffic
- A mesh that only secures external traffic
- A sidecar-less mesh architecture using shared node-level proxies (ztunnel) (Correct answer)
- A mesh deployed without a control plane
Correct answer: A sidecar-less mesh architecture using shared node-level proxies (ztunnel)
Istio ambient mesh removes per-pod sidecars by using a per-node ztunnel proxy for L4 and optional waypoint proxies for L7 policies.
Question 29: In Kubernetes and Cloud Native Associate, what is the PRIMARY purpose of conducting regular safety drills and exercises?
- To evaluate employee performance reviews
- To reduce daily workload
- To satisfy insurance requirements only
- To ensure personnel can respond effectively in emergencies (Correct answer)
Correct answer: To ensure personnel can respond effectively in emergencies
Regular safety drills ensure that all personnel are prepared to respond effectively during actual emergencies. Practice builds muscle memory, identifies gaps in emergency procedures, and improves overall response times.
Question 30: Which principle states that users should only have access necessary for their role?
- Defense in depth
- Need to share
- Principle of least privilege (Correct answer)
- Separation of duties
Correct answer: Principle of least privilege
The principle of least privilege ensures users only have the minimum access rights needed to perform their job functions, limiting potential damage.
Kubernetes and Cloud Native Associate (KCNA)
The KCNA is an entry-level certification from CNCF and the Linux Foundation that validates foundational knowledge of Kubernetes, container orchestration, and cloud native technologies. It covers Kubernetes fundamentals, container orchestration, cloud native architecture, observability, and application delivery.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds