CKA Troubleshooting Practice Question
A Deployment's pod is stuck in Pending state. 'kubectl describe pod' shows Events: '0/4 nodes are available: 1 node(s) had taint {node-role.kubernetes.io/control-plane: }, that the pod didn't tolerate, 3 Insufficient memory'. What is the likely fix?
⚠ Common exam trap
The trap here is that candidates focus on the taint error and assume the control-plane node is the bottleneck, ignoring the more critical 'Insufficient memory' message that points to a resource shortage on the worker nodes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increase the memory limit of the pod or add more worker nodes
The error '3 Insufficient memory' indicates that three worker nodes lack the required memory to schedule the pod. Increasing the pod's memory limit (if it's set too high) or adding more worker nodes directly addresses the resource shortage. The control-plane node's taint is irrelevant because the pod is not trying to schedule there; the issue is insufficient memory on the available worker nodes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove the taint from the control-plane node
Why it's wrong here
Removing the control-plane taint would let workloads schedule onto the control plane, but the three worker nodes still report Insufficient memory, so the pod remains Pending. Untainting suits single-node clusters where the control plane must also host workloads, not a memory-constrained multi-node cluster.
- ✗
Add a toleration for the control-plane taint to the pod spec
Why it's wrong here
Tolerating the control-plane taint only makes that one node eligible; the scheduler still rejects it because the control plane typically reserves capacity, and the three worker nodes remain memory-starved. Tolerations suit scheduling onto tainted dedicated nodes, not resolving Insufficient memory elsewhere.
- ✗
Set nodeSelector to schedule on control-plane nodes
Why it's wrong here
A nodeSelector targeting control-plane nodes does not bypass the control-plane taint, so the pod stays Pending; the memory shortage on the three workers is untouched. Node selectors suit pinning pods to labelled nodes, not overriding taints or freeing cluster memory.
Go deeper
Related to this question
Learn chapter
Installing Kubernetes with kubeadm
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.