20+ practice questions focused on Container Orchestration — one of the most tested topics on the Kubernetes and Cloud Native Associate KCNA exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Container Orchestration PracticeAn application running in a Kubernetes pod needs to access a database that is deployed on a VM outside the cluster. The database IP is stable. Which is the best way to expose the database to the pod?
Explanation: A Service of type ExternalName provides a DNS-based abstraction for external resources, mapping a Kubernetes service name to an external DNS name (the database hostname). This allows the pod to access the database via a stable in-cluster DNS name without needing to manage IP changes or network policies for external endpoints. It is the simplest and most Kubernetes-native way to expose a stable external IP to a pod.
A team notices that a ReplicaSet is not creating the desired number of pods. The ReplicaSet YAML is correctly configured with replicas: 3. The cluster has sufficient resources. What is the most likely cause?
Explanation: An invalid image pull secret in the pod template prevents the kubelet from authenticating with the container registry, causing the pod creation to fail. The ReplicaSet controller attempts to create pods, but the scheduler cannot pull the image, so the pods remain in a pending or ImagePullBackOff state, never reaching the desired count of 3.
Which TWO of the following are valid ways to expose a set of pods as a network service in Kubernetes?
Explanation: A Service of type NodePort exposes a set of pods on a static port on each node's IP address, making the service accessible from outside the cluster. This is a valid Kubernetes resource for exposing pods as a network service, as it creates a mapping from a node port to the ClusterIP and then to the target pods.
Which TWO of the following are valid methods to expose a set of pods to external traffic in Kubernetes?
Explanation: A LoadBalancer Service (option A) is correct because it provisions an external load balancer (via the cloud provider's controller) that routes external traffic to the backing pods, giving them a publicly reachable IP. A NodePort Service (option B) is also correct because it opens a static port (default range 30000–32767) on every node's IP, allowing external clients to reach the pods through <NodeIP>:<NodePort>. A Headless Service (option C) is not correct because setting clusterIP: None only returns pod IPs directly via DNS for stateful/discovery use and provides no external exposure. A ClusterIP Service (option D) is not correct because it is only reachable from within the cluster on an internal virtual IP. Ingress (option E) is not correct on its own because it is an HTTP/HTTPS routing layer that still requires an externally exposed Service (typically LoadBalancer or NodePort) or ingress controller endpoint to receive external traffic.
Your organization runs a microservices application in a Kubernetes cluster with 5 worker nodes. Each microservice is deployed as a Deployment with 3 replicas. Recently, users report intermittent timeouts when accessing the frontend service. The frontend communicates with a backend service via ClusterIP. You check the backend pods and find that one of the three replicas is in CrashLoopBackOff. The other two backend pods are healthy. The frontend deployment has no readiness or liveness probes. You notice that the frontend's connection pool to the backend has a timeout of 5 seconds. The crashing backend pod logs show an occasional NullPointerException that causes the container to restart, but the pod becomes ready after restart within 2 seconds. However, the frontend's connection pool does not evict unhealthy connections quickly. What is the best course of action to reduce timeouts?
Explanation: The intermittent timeouts occur because the frontend's connection pool holds stale connections to the backend pod that is in CrashLoopBackOff. Although the pod restarts and becomes ready within 2 seconds, the frontend does not detect that the old connection is broken and continues to use it until the 5-second timeout expires. Adding a readiness probe to the backend Deployment ensures that Kubernetes only sends traffic to pods that pass the health check; when the pod fails the probe, it is removed from the ClusterIP's endpoints, preventing the frontend from routing requests to it and thus eliminating the timeouts.
+15 more Container Orchestration questions available
Practice all Container Orchestration questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Container Orchestration. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Container Orchestration questions on the KCNA frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Container Orchestration is tested as part of the Kubernetes and Cloud Native Associate KCNA blueprint. Practicing with targeted Container Orchestration questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free KCNA practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Container Orchestration is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Container Orchestration practice session with instant scoring and detailed explanations.
Start Container Orchestration Practice →