Kubernetes and Cloud Native Associate Free Sample Questions

20 free sample questions300 in the full practice test

Try simulator

KCNA Sample Questions

  1. Question 1

    A financial services company is adopting cloud native practices and needs to ensure that all container images deployed to their production Kubernetes cluster are from a trusted, internal registry and have been scanned for critical vulnerabilities. Which combination of CNCF projects is best suited to enforce this policy at the time of deployment?

    Answer and explanation

    Correct answer: B

    Harbor is a CNCF graduated project that provides a private container registry with integrated vulnerability scanning (like Trivy or Clair). Open Policy Agent (OPA) can be used as a Kubernetes admission controller to enforce policies, such as rejecting pods that attempt to use images from untrusted registries or images with known critical vulnerabilities. This combination directly addresses the requirements.

  2. Question 2

    A DevOps team is managing a microservices application where different services are updated independently. They observe that a new version of the 'user-profile' service is causing intermittent failures in the 'order-processing' service. To improve debugging, they need to trace a single user request as it flows through multiple services. Which CNCF-graduated project is specifically designed to address this cross-service tracing requirement?

    Answer and explanation

    Correct answer: C

    Jaeger is a CNCF-graduated project for distributed tracing. It allows developers to monitor and troubleshoot transactions in complex distributed systems, like microservices. It visualizes the path of a request as it travels through different services, which is exactly what the team needs to debug the intermittent failures. Prometheus is for metrics, and Fluentd is for logging.

  3. Question 3

    A platform team is implementing GitOps using Flux. They have structured their Git repository with a clusters/ directory containing configurations for dev and prod clusters, and an apps/ directory with base manifests for each application. What is the primary GitOps mechanism Flux uses to apply these manifests to the correct clusters and keep them synchronized?

    Answer and explanation

    Correct answer: C

    The core principle of pull-based GitOps, as implemented by tools like Flux and Argo CD, is an in-cluster operator (or agent). This operator periodically pulls the state of the Git repository and compares it to the live state of the Kubernetes cluster. If there's a difference (drift), the operator takes action to make the cluster state match the 'source of truth' in Git. This is known as reconciliation.

  4. Question 4

    Multiple answers

    Which of the following are key principles of a cloud native architecture according to the CNCF? (Select TWO)

    Answer and explanation

    Correct answers: A, C

  5. Question 5

    True or False: In Kubernetes, a Service of type ClusterIP is accessible from outside the cluster by default.

    Answer and explanation

    Correct answer: B

    A Service of type ClusterIP exposes the Service on a cluster-internal IP. This makes the Service reachable only from within the cluster. To expose a Service to the outside world, you must use other Service types like NodePort or LoadBalancer, or an Ingress resource.

  6. Question 6

    An e-commerce platform experiences high traffic during flash sales. The application backend, running as a Deployment, needs to scale automatically based on CPU utilization. Which Kubernetes resource is used to achieve this horizontal scaling?

    Answer and explanation

    Correct answer: B

    The Horizontal Pod Autoscaler (HPA) automatically scales the number of pods in a replication controller, deployment, replica set or stateful set based on observed CPU utilization (or with custom metrics support, on some other application-provided metrics). This is the standard Kubernetes mechanism for scaling out stateless applications based on load.

  7. Question 7

    A developer needs to provide an application running in a pod with a database password. To follow security best practices, this sensitive information should not be stored in the container image or in a ConfigMap. What is the appropriate Kubernetes resource for securely managing and injecting this password into the pod?

    Answer and explanation

    Correct answer: A

    Kubernetes Secrets are designed specifically for storing and managing sensitive information, such as passwords, OAuth tokens, and ssh keys. They can be mounted as data volumes or exposed as environment variables to a container in a Pod. While they are base64 encoded by default (not encrypted), they are the designated Kubernetes object for handling sensitive data separately from pods and ConfigMaps.

  8. Question 8

    A site reliability engineer (SRE) is using Prometheus to monitor a Kubernetes cluster. They want to create an alert that fires when a pod has been in a CrashLoopBackOff state for more than 15 minutes. To achieve this, the SRE needs to query a specific metric that tracks the state of containers. Which component is primarily responsible for exposing these container-level metrics to Prometheus?

    Answer and explanation

    Correct answer: C

    The kubelet, which runs on every worker node, is responsible for managing the lifecycle of pods on that node. It exposes a /metrics endpoint that provides detailed metrics about the node itself and the containers running on it, including container states, restarts, and resource usage. Prometheus is configured to scrape this endpoint on each node to collect these vital metrics for monitoring and alerting.

  9. Question 9

    What is the primary role of a Container Network Interface (CNI) plugin in a Kubernetes cluster?

    Answer and explanation

    Correct answer: D

    The Container Network Interface (CNI) is a standard for writing plugins to configure network interfaces for Linux containers. In Kubernetes, the kubelet uses a CNI plugin (like Calico, Flannel, or Cilium) to handle networking tasks when a pod is created or destroyed. This includes assigning an IP address to the pod, setting up routes, and ensuring it can communicate with other pods according to the cluster's networking model.

  10. Question 10

    A company wants to deploy a new feature to a small subset of users before rolling it out to everyone. This strategy allows them to test the feature's stability and gather feedback with minimal risk. Which application delivery strategy does this describe?

    Answer and explanation

    Correct answer: B

    A Canary Release is a deployment strategy where the new version of an application is gradually rolled out to a small subset of users. Traffic is selectively routed to the new version, allowing teams to monitor its performance and stability in a real production environment. If the new version performs well, traffic is incrementally shifted until all users are on the new version. This matches the described scenario.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 300 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon