Courseiva
Troubleshooting →mediumMultiple Select

CKA Troubleshooting Practice Question

A pod is in 'Pending' state. 'kubectl describe pod' shows: '0/3 nodes are available: 1 Insufficient memory, 2 node(s) had taint {node-role.kubernetes.io/control-plane: }, that the pod didn't tolerate.' Which THREE actions would resolve the issue? (Choose three)

⚠ Common exam trap

CKA often tests whether candidates confuse 'node selector' with 'toleration' — a selector narrows eligible nodes but never overrides a taint, so it cannot fix a taint-based Pending condition.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Remove the taint from the control-plane nodes.

The scheduler message shows two distinct problems: one node has Insufficient memory, and two nodes carry the taint node-role.kubernetes.io/control-plane that the pod does not tolerate. Option A is correct because removing that taint from the control-plane nodes makes them eligible for scheduling, directly eliminating the 'didn't tolerate' rejection. Option B is correct because lowering the pod's memory request lets it fit on the node that currently reports Insufficient memory, resolving that filter failure. Option D is correct because adding a matching toleration (e.g., key node-role.kubernetes.io/control-plane with the appropriate effect) allows the pod to be scheduled onto the tainted control-plane nodes without changing the cluster. Option C is wrong because increasing the CPU request only makes scheduling harder and does not address either reported failure. Option E is wrong because a node selector matching control-plane nodes does not bypass the taint; without a toleration the pod would still be rejected by those nodes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Remove the taint from the control-plane nodes.

    Why this is correct

    Removing the control-plane taint lets the scheduler place the pod on those nodes, directly resolving the 'taint the pod didn't tolerate' rejection. It addresses one of the two stated scheduling failures, freeing capacity that the Insufficient memory node cannot provide.

  • ✓

    Decrease the memory request of the pod.

    Why this is correct

    Lowering the pod's memory request makes it schedulable on the node reporting Insufficient memory. This directly resolves the first scheduling failure named in the stem, allowing the pod to fit within that node's allocatable memory.

  • ✗

    Increase the CPU request of the pod.

    Why it's wrong here

    The scheduler reports insufficient memory and untolerated control-plane taints; CPU requests are not part of either failure message, so raising them changes nothing about schedulability. CPU requests matter when nodes report insufficient CPU. The pod remains Pending because no node satisfies its memory request or tolerates the taint.

  • ✓

    Add a toleration to the pod for the control-plane taint.

    Why this is correct

    Adding a toleration lets the scheduler place the pod on control-plane nodes whose taint currently repels it. This directly addresses the two tainted nodes reported in the stem, expanding eligible capacity beyond the single memory-starved node.

  • ✗

    Add a node selector to the pod that matches the control-plane nodes.

    Why it's wrong here

    A node selector matching control-plane nodes does not remove the node-role.kubernetes.io/control-plane taint; the scheduler still rejects the pod unless a matching toleration is added. Node selectors constrain placement to labelled nodes, which is useful for dedicated hardware or topology, but tolerations are what permit scheduling onto tainted nodes.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.