CKA Practice Question: Cluster Architecture, Installation and Configuration
A developer created a ServiceAccount named 'app-sa' in the 'dev' namespace. They want a pod to use this ServiceAccount. Which field in the pod spec should be set?
⚠ Common exam trap
Test-takers frequently confuse the deprecated `spec.serviceAccount` field (which still works in older clusters but is removed in recent versions) with the correct `spec.serviceAccountName`, or invent a non-existent field like `spec.accountName` due to similarity with other Kubernetes resource specs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
spec.serviceAccountName
The `spec.serviceAccountName` field in a Pod spec is the standard way to assign a specific ServiceAccount to a Pod. When this field is set, the Pod's containers will use the token of that ServiceAccount for API authentication. If omitted, the Pod defaults to the `default` ServiceAccount in its namespace.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
spec.serviceAccount
Why it's wrong here
spec.serviceAccount is a historical field from early Kubernetes API versions that has been deprecated and removed from PodSpec. In current Kubernetes (1.22+), this field is no longer recognized; setting it has no effect, and the API server expects serviceAccountName instead. Using this field will either fail validation or be ignored, so it cannot properly assign the 'app sa' ServiceAccount to the pod.
- ✗
spec.authentication.serviceAccount
Why it's wrong here
spec.authentication.serviceAccount is an invalid path because PodSpec has no 'authentication' sub-object containing a 'serviceAccount' key. The Pod API schema defines serviceAccountName and automountServiceAccountToken directly under the pod spec, not nested in an authentication block. Referencing this path causes a schema validation error from the API server, so it cannot assign a ServiceAccount.
- ✓
spec.serviceAccountName
Why this is correct
spec.serviceAccountName is the canonical field in PodSpec that tells the kubelet and kube-apiserver which ServiceAccount to attach to the pod. When set to 'app sa', the pod will mount the token and credentials of that ServiceAccount, enabling authenticated access to the Kubernetes API. If omitted, the default ServiceAccount in the namespace is used automatically, but explicitly setting it here binds the pod to 'app sa'.
- ✗
spec.accountName
Why it's wrong here
spec.accountName is not a defined field in PodSpec or any Kubernetes API resource. There is no generic 'accountName' property; the correct and only valid way to specify a ServiceAccount is through serviceAccountName. Because this path does not exist, the API server will reject the Pod manifest with an unknown field error, making it entirely ineffective.
About these practice questions
Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.