CKA Practice Question: Cluster Architecture, Installation & Configuration
An administrator needs to initialize a new Kubernetes control plane node using kubeadm. Which of the following is the correct command to initialize the control plane with a specific pod network CIDR of 10.244.0.0/16?
⚠ Common exam trap
It's easy for candidates to confuse `--pod-network-cidr` with `--service-cidr` or inventing flags like `--cidr` or `--network-cidr`, leading candidates to pick options that either do not exist or configure the wrong network range.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubeadm init --pod-network-cidr=10.244.0.0/16
`kubeadm init` uses the `--pod-network-cidr` flag to specify the CIDR range for the pod network, which is required by many CNI plugins (e.g., Flannel defaults to 10.244.0.0/16). This flag tells kubeadm to configure the control plane components (like the controller manager) to allocate pod IPs from this range.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
kubeadm init --pod-network-cidr=10.244.0.0/16
Why this is correct
Kubeadm's --pod-network-cidr flag defines the IPv4 CIDR range from which pod IP addresses are allocated. It is required when installing a pod network add-on such as Flannel, which commonly expects the 10.244.0.0/16 range. The kube-controller-manager then uses this range to assign per-node subnets, enabling cross-node pod communication.
- ✗
kubeadm init --cidr=10.244.0.0/16
Why it's wrong here
There is no generic --cidr flag in kubeadm init; the kubeadm command-line parser rejects unknown flags immediately. If an administrator runs this, kubeadm will fail with an error listing the flag as invalid. The correct way to specify the pod network range is the singular --pod-network-cidr flag, not a shorthand or alternate version.
- ✗
kubeadm init --network-cidr=10.244.0.0/16
Why it's wrong here
kubeadm does not recognize --network-cidr as a valid flag; this name is not part of its configuration schema. While other networking components like kube-proxy use different flags, kubeadm only exposes the pod subnet through --pod-network-cidr. Using this misspelled or misremembered flag results in a 'flag provided but not defined' error and aborts initialization.
- ✗
kubeadm init --service-cidr=10.244.0.0/16
Why it's wrong here
The --service-cidr flag configures the virtual IP range for ClusterIP services, with a default of 10.96.0.0/12, and has no effect on pod IP addressing. Passing 10.244.0.0/16 to it would assign that range to services, leaving the pod network unspecified and causing the CNI plugin to fail or misbehave. The pod CIDR must be set with --pod-network-cidr, and it should not overlap with the service CIDR.
Visual reference
Go deeper
Related to this question
Learn chapter
Network Policies and Secure Connectivity
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
Key term
kubeadm Cluster Setup
kubeadm is a command-line tool that helps you create and manage a Kubernetes cluster by automating the setup of control plane and worker nodes.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.