Courseiva
Troubleshooting →mediumMultiple Select

CKA Troubleshooting Practice Question

A pod is in ImagePullBackOff. Which TWO of the following are possible causes? (Select 2)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The image is in a private registry and no imagePullSecrets are defined

Common causes: invalid image tag (typo) and authentication failure when the image is in a private registry.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The node has insufficient memory

    Why it's wrong here

    Insufficient node memory is a scheduling or runtime constraint: if no node has enough allocatable memory to meet the pod's requests, the pod stays Pending and is never assigned; if memory pressure occurs after scheduling, the container is killed with an OOMKilled reason. ImagePullBackOff, however, is an image acquisition failure that happens before the container ever starts, so it cannot be caused by memory shortages.

  • ✓

    The image is in a private registry and no imagePullSecrets are defined

    Why this is correct

    When an image resides in a private registry, the kubelet must authenticate itself using image pull secrets specified in the pod's spec via `imagePullSecrets`. If those secrets are missing or not attached to the pod, the registry responds with an authorization error (e.g., "unauthorized: authentication required"), and the kubelet reports ErrImagePull before entering ImagePullBackOff. This is a common production misconfiguration because merely having the secret in the namespace does not grant the pod access.

  • ✗

    The pod has a resource limit that is too low

    Why it's wrong here

    Resource limits (like `resources.limits.cpu` and `.memory`) are enforced by the kubelet and container runtime only after the container is created and running. If the container exceeds its memory limit, it is terminated by the OOM killer, resulting in an OOMKilled state, not ImagePullBackOff; CPU limits cause throttling, not pull failures. Since ImagePullBackOff occurs before container start, a too-low limit is irrelevant to this error condition.

  • ✓

    The image tag is misspelled

    Why this is correct

    A misspelled image name or tag, such as `nginx:latst` or `registry.example.com/app:verison`, makes the registry look for a non-existent manifest and return a "manifest unknown" or "not found" error. The kubelet retries a few times and then places the container into ImagePullBackOff with an exponential backoff, exactly as it does for any invalid image reference. This fails even for public images, so it is a distinct but very common cause.

  • ✗

    The kubelet is not running

    Why it's wrong here

    If the kubelet were not running, the node would be reported NotReady, and the control plane would not be able to schedule or manage pods on it; existing pods would be marked Unknown rather than entering ImagePullBackOff. ImagePullBackOff is itself a status set by the kubelet after failed container image pulls, so its presence proves the kubelet is alive and actively attempting to pull images. Therefore, a stopped kubelet is incompatible with this error state.

About these practice questions

This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.