CKA Practice Question: Cluster Architecture, Installation and Configuration
A pod is stuck in 'Pending' state. 'kubectl describe pod' shows '0/1 nodes are available: 1 node(s) had taint {node.kubernetes.io/unreachable: }, that the pod didn't tolerate'. What does this indicate?
⚠ Common exam trap
Test-takers frequently confuse taints related to resource pressure (like memory or disk) with the unreachable taint, or assume 'Pending' means the pod is scheduled but waiting for resources, when in fact the specific taint name directly indicates a node reachability issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The node is not reachable by the control plane
The error message indicates that the node has a taint of `node.kubernetes.io/unreachable`, which is automatically added by the node controller when the control plane cannot communicate with the node (e.g., due to network failure or kubelet being down). The pod remains in 'Pending' because no node is available that tolerates this taint, meaning the node is unreachable from the control plane. This matches option C.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The pod has been successfully scheduled to the node
Why it's wrong here
A pod in Pending means the Kubernetes scheduler has not yet successfully assigned it to a node; the scheduler updates the PodScheduled condition and sets the nodeName only after placement. If it had been scheduled, the pod would typically progress to ContainerCreating or Running, not remain in Pending. The observed unreachable taint further proves the scheduler refused placement due to node unavailability.
- ✗
The node has insufficient resources and is tainted
Why it's wrong here
Insufficient resources on a node produce scheduler events like 'Insufficient cpu' or 'Insufficient memory', and the node remains ready; it does not get a taint. The 'unreachable' taint is applied by the node controller when the control plane loses communication with the node. A taint alone also does not cause resource exhaustion—it marks a scheduling restriction, rather than a capacity shortage, so this option conflates two separate failure modes.
- ✓
The node is not reachable by the control plane
Why this is correct
The node.kubernetes.io/unreachable taint is set by the node controller when it stops receiving heartbeats from the kubelet, meaning the control plane can no longer reach or manage the node. Pods without a matching toleration are blocked from scheduling onto that node, leaving them Pending. This matches the kubectl describe output showing an unreachable taint, confirming the root cause is loss of control-plane connectivity to the node.
- ✗
The node does not exist
Why it's wrong here
If the node object did not exist, the scheduler would report '0/1 nodes are available' or 'no matching node found' in events, and there would be no node name or taint information referencing it. The presence of an 'unreachable' taint requires the node object to exist in etcd so the node controller can apply status and taints. Therefore, the issue is not a missing node but a node that exists yet is not communicating with the control plane.
Go deeper
Related to this question
Learn chapter
Network Policies and Secure Connectivity
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
Key term
kubectl Command Reference
kubectl is the command-line tool used to interact with and manage Kubernetes clusters by sending commands to the Kubernetes API.
About these practice questions
Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.