20+ practice questions focused on Cluster Architecture, Installation and Configuration — one of the most tested topics on the Certified Kubernetes Administrator CKA exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Cluster Architecture, Installation and Configuration PracticeAn administrator runs 'kubectl drain node01 --ignore-daemonsets --force' to prepare node01 for maintenance. However, a pod running a critical application is evicted and becomes unschedulable. Which flag could prevent eviction of that specific pod?
Explanation: The `--delete-local-data=false` flag prevents the eviction of pods that use emptyDir volumes or local data. By default, `kubectl drain` evicts all pods except those managed by DaemonSets, and the `--force` flag bypasses checks that would normally protect pods with local storage. Setting this flag to false ensures that pods with local data (like the critical application) are not evicted during the drain operation.
A cluster was upgraded from v1.28 to v1.29 using kubeadm. After upgrading the control plane, nodes remain at v1.28. What is the correct next step to upgrade a worker node?
Explanation: After upgrading the control plane with kubeadm, worker nodes must be upgraded individually. The correct sequence is to SSH into the worker node, run 'kubeadm upgrade node' to upgrade the kubelet configuration and static pod manifests, then upgrade the kubelet and kubectl binaries (typically via the package manager), and finally restart the kubelet to pick up the new version. This ensures the node runs the same Kubernetes version as the control plane.
A cluster is running etcd without TLS. The admin wants to take a snapshot backup. Which command is correct?
Explanation: `ETCDCTL_API=3 etcdctl snapshot save` is the proper command to take a snapshot backup of an etcd cluster using the v3 API. Since the cluster is running without TLS, the command does not require additional flags like `--cacert` or `--cert`, but the default endpoint is `http://127.0.0.1:2379`, which is used implicitly. The v3 API is required because etcd v3 stores data in a different format than v2, and `snapshot save` captures the full key-value store for disaster recovery.
Which THREE are valid methods to authenticate a user to the Kubernetes API server? (Select 3)
Explanation: Option A (Bearer tokens, e.g., service account tokens) is correct because the API server accepts bearer tokens in the Authorization header, and service account tokens are a standard, built-in authentication method for workloads and users. Option C (Client certificates) is correct because the API server supports X.509 client certificate authentication, typically configured via --client-ca-file, where the certificate's CN becomes the username and O becomes the group. Option E (OpenID Connect (OIDC) tokens) is correct because the API server can validate OIDC ID tokens issued by an identity provider using flags such as --oidc-issuer-url and --oidc-client-id, making OIDC a supported authentication strategy. Option B (Username/password via HTTP Basic Auth) is not a valid method here because HTTP Basic Auth was deprecated and removed from Kubernetes, so it is no longer an accepted authentication mechanism. Option D (Static password file) is also not valid because the --basic-auth-file static password mechanism was deprecated and removed, so it cannot authenticate users to current API servers.
Which TWO commands are valid for managing nodes in Kubernetes? (Select two.)
Explanation: Option A, `kubectl drain <node>`, is correct because it safely evicts all pods from a node (respecting PodDisruptionBudgets) and marks the node as unschedulable, which is the standard procedure before maintenance or decommissioning. Option C, `kubectl cordon <node>`, is correct because it marks a node as unschedulable so no new pods are scheduled onto it, while leaving existing pods running. Option B is not a valid node-management command in the sense tested here—`kubectl delete node` removes the Node object from the API server but does not perform graceful pod eviction, so it is not the intended answer. Option D is incomplete: `kubectl taint` requires a key/value/effect specification (e.g., `kubectl taint nodes <node> key=value:NoSchedule`) and is not a standalone valid command. Option E is invalid because `kubectl scale` operates on scalable resources like Deployments, ReplicaSets, and StatefulSets, not on nodes.
+15 more Cluster Architecture, Installation and Configuration questions available
Practice all Cluster Architecture, Installation and Configuration questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Cluster Architecture, Installation and Configuration. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Cluster Architecture, Installation and Configuration questions on the CKA frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Cluster Architecture, Installation and Configuration is tested as part of the Certified Kubernetes Administrator CKA blueprint. Practicing with targeted Cluster Architecture, Installation and Configuration questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CKA practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Cluster Architecture, Installation and Configuration is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Cluster Architecture, Installation and Configuration practice session with instant scoring and detailed explanations.
Start Cluster Architecture, Installation and Configuration Practice →