Courseiva

CKA Practice Question: Cluster Architecture, Installation and Configuration

A node named 'node1' is having issues. You want to prevent any new pods from being scheduled onto it without affecting running pods. Which command should you use?

⚠ Common exam trap

Test-takers frequently confuse `cordon` with `drain` or `taint`, thinking that draining is required to prevent scheduling, or that tainting is the only way to achieve this, but `cordon` is the simplest and most direct command for marking a node unschedulable without affecting running pods.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl cordon node1

The `kubectl cordon node1` command marks the node as unschedulable, preventing new pods from being scheduled onto it while leaving existing pods running. This is the correct approach when you need to isolate a node for maintenance without disrupting current workloads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl drain node1

    Why it's wrong here

    Running `kubectl drain node1` goes beyond simply marking the node as unschedulable; it actively evicts all running pods from the node (except daemonsets) and reschedules them elsewhere. This is too disruptive if the goal is merely to prevent new workloads from landing on the node while allowing existing ones to continue running or being investigated.

  • ✓

    kubectl cordon node1

    Why this is correct

    The `kubectl cordon node1` command is the standard and safest way to mark a node as unschedulable. It updates the node's spec to set `unschedulable: true`, which prevents the Kubernetes scheduler from placing any new pods onto it, while leaving all currently running pods completely unaffected.

  • ✗

    kubectl taint nodes node1 key=value:NoSchedule

    Why it's wrong here

    `kubectl taint nodes node1 key=value:NoSchedule` is incorrect because, while it prevents pods without a matching toleration from being scheduled, it does not prevent *all* new pods. Pods with a toleration for `key=value` would still be scheduled onto 'node1'. This command is useful for dedicating nodes to specific workloads by requiring pods to explicitly tolerate the taint, such as reserving a node for control plane components or specialised hardware, but it does not achieve a complete scheduling block for all new pods as required by the scenario.

  • ✗

    kubectl delete node node1

    Why it's wrong here

    Executing `kubectl delete node node1` completely removes the node object from the Kubernetes API server's registry. This does not gracefully stop scheduling; instead, it causes the control plane to lose track of the node entirely, leading to immediate rescheduling of its pods and potentially leaving the physical or virtual machine in an unmanaged, orphaned state.

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.