CKA Workloads and Scheduling Practice Question
A pod is stuck in Pending state. You run 'kubectl describe pod my-pod' and see the event: '0/4 nodes are available: 1 node(s) had taint {gpu: true} that the pod didn't tolerate, 3 node(s) had resource pressure.'. What is the most likely cause?
⚠ Common exam trap
CKA often tests the distinction between taint/toleration issues and other scheduling constraints (like nodeSelector or affinity), and the trap here is that candidates may overlook the resource pressure component and focus only on the taint, or confuse the event message with a nodeSelector mismatch.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The pod needs a toleration for the gpu taint, and nodes have resource constraints.
The event message explicitly states that 1 node has a taint (gpu: true) that the pod does not tolerate, and 3 nodes have resource pressure (e.g., memory, disk, or PID exhaustion). A pod remains in Pending state when no node can satisfy its scheduling requirements; adding a toleration for the gpu taint would allow scheduling on that node, but the resource pressure on the other nodes must also be resolved (e.g., by freeing resources or increasing capacity).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The pod has a nodeSelector that doesn't match any node.
Why it's wrong here
While an unmatched nodeSelector can cause a pod to remain in a Pending state, the scheduler events in the kubectl describe output specifically highlight taint mismatches and resource constraints rather than node selector filtering. A node selector mismatch would trigger a '0/N nodes are available: N node(s) didn't match Pod's node selector' event, which is not the root cause described here.
- ✗
The pod is using a deprecated API version.
Why it's wrong here
Submitting a manifest with a deprecated or invalid API version is rejected immediately by the kube-apiserver during the admission phase, preventing the object from being created at all. It would never transition to a Pending state because the resource would not exist in the cluster's etcd database.
- ✓
The pod needs a toleration for the gpu taint, and nodes have resource constraints.
Why this is correct
The scheduler cannot place the pod because the available nodes either carry a gpu taint that the pod does not tolerate, or they lack sufficient CPU/memory capacity to satisfy the pod's resource requests. To resolve this, you must add the appropriate tolerations to the pod specification and ensure the cluster has nodes with adequate allocatable resources.
- ✗
The pod's image pull secret is missing.
Why it's wrong here
A missing image pull secret allows the pod to be successfully scheduled to a node, meaning it transitions out of the Pending state. Once scheduled, the kubelet on the destination node will fail to pull the container image, resulting in a Waiting state with reasons like ErrImagePull or ImagePullBackOff rather than remaining Pending.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.