CKA Workloads and Scheduling Practice Question
A pod is in Pending state. You run 'kubectl describe pod' and see the event: '0/4 nodes are available: 1 node(s) had taint {node-role.kubernetes.io/master: }, that the pod didn't tolerate, 3 node(s) had taint {node.kubernetes.io/not-ready: }.'. What is the most likely reason?
⚠ Common exam trap
A common mix-up: candidates confuse taint/toleration issues with resource insufficiency, but the event message explicitly names taints, not resource shortages, making D the only correct answer based on the provided event details.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The pod does not have tolerations for the taints on the available nodes
The pod is in Pending state because the scheduler cannot find a node that meets all scheduling constraints. The event explicitly states that 1 node has a taint `node-role.kubernetes.io/master` and 3 nodes have a taint `node.kubernetes.io/not-ready`, and the pod does not have corresponding tolerations. Without tolerations, the pod is not allowed to schedule on any of these nodes, leaving no available node.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The pod's container image pull failed
Why it's wrong here
A failed image pull generates kubelet-level events such as 'Failed to pull image' or 'ErrImagePull', and the pod's status typically becomes ImagePullBackOff, not Pending with scheduler events about taints. Taint/toleration mismatches are reported by the kube-scheduler before the image is even fetched, because the pod cannot be placed on any node. Therefore the event stream described in the question directly contradicts this option.
- ✗
The cluster is out of CPU capacity
Why it's wrong here
If the cluster were out of CPU capacity, the scheduler's events would state something like '0/3 nodes are available: insufficient cpu' or 'Insufficient memory', with resource-related fit errors per node. The describe output explicitly references taints on nodes, which is a different scheduling predicate that does not involve node capacity calculations. Thus this option misreads the scheduler's reason for refusing pod placement.
- ✗
The pod's resource requests are too high for any node
Why it's wrong here
Resource requests that are too high for any node appear in scheduler events as 'Insufficient cpu' or 'Insufficient memory' per node, and the describe output would list those fit errors rather than taint mentions. Taint/toleration checks occur before resource fit during the scheduling cycle and produce messages like '3 node(s) had taint'—a completely distinct signal. Since the observed events cite taints instead of resource shortfalls, this explanation is not supported by the output.
- ✓
The pod does not have tolerations for the taints on the available nodes
Why this is correct
The scheduler reports that available nodes are tainted and the pod has no matching tolerations, often as '0/3 nodes available: 3 node(s) had taint {key=value:effect}, that the pod didn't tolerate.' Taints are applied to nodes with `kubectl taint nodes ...`, and only pods whose spec contains a toleration matching the taint's key, value, and effect can be scheduled there. Adding an appropriate toleration will let the scheduler place the pod, so this is the correct diagnosis.
Go deeper
Related to this question
Learn chapter
Troubleshooting Cluster and Node Issues
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
kubectl Command Reference
kubectl is the command-line tool used to interact with and manage Kubernetes clusters by sending commands to the Kubernetes API.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.