Courseiva

CKA Practice Question: Cluster Architecture, Installation and Configuration

An administrator needs to upgrade a Kubernetes cluster from v1.28 to v1.29 using kubeadm. Which of the following steps is performed FIRST?

⚠ Common exam trap

It's easy for candidates to assume draining or cordoning nodes is the first step, but the CKA exam emphasizes that the upgrade plan must be run first to validate the upgrade path and avoid irreversible errors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run 'kubeadm upgrade plan' on the first control plane node

Before any upgrade operations, kubeadm requires an assessment of the cluster's upgrade path and potential issues. 'kubeadm upgrade plan' on the first control plane node checks the current and target versions, validates the upgrade feasibility, and displays the upgrade steps and any manual interventions needed. This must be done first to ensure the upgrade is safe and to identify any version skew or configuration problems before proceeding.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Run 'kubeadm upgrade plan' on the first control plane node

    Why this is correct

    Running 'kubeadm upgrade plan' on the first control plane node is the correct initial step because it checks the current cluster version, validates that the upgrade path is supported, and lists the available kubeadm versions and the components (etcd, control plane, kubelet) that will be upgraded, along with any manual steps required. It also verifies that the node is healthy and gives you a preview of the exact upgrade commands, making it a safe, non-destructive first action before any draining or version changes.

  • ✗

    Drain all worker nodes

    Why it's wrong here

    Draining all worker nodes is a later step in the upgrade process, typically done per-node or per-pool after the control plane has been upgraded, because draining removes pods from a node and marks it unschedulable, which would disrupt workloads unnecessarily before the control plane is ready to reschedule them. The kubeadm upgrade process requires control plane components to be upgraded first and does not require all nodes to be drained upfront; doing so prematurely is disruptive and not a prerequisite. In fact, kubeadm does not even manage worker node kubelet upgrades; those are done by draining each worker node and then upgrading its kubelet and kube-proxy iteratively.

  • ✗

    Run 'kubectl cordon' on all nodes

    Why it's wrong here

    Cordonning all nodes makes them unschedulable but does not evict existing pods, so it is not a useful initial step for a kubeadm upgrade; it needlessly blocks new workloads cluster-wide without providing any upgrade benefit. The control plane upgrade itself does not require the cluster to be cordoned — kubeadm upgrade plan/apply will run on the control plane node and handle its components. Cordon is typically used to safely drain or decommission specific nodes, not as a cluster-wide prep step for a kubeadm version upgrade.

  • ✗

    Upgrade kubelet on the first control plane node

    Why it's wrong here

    Upgrading the kubelet on the control plane node is out of order because kubeadm upgrade apply first upgrades the control plane components (apiserver, controller-manager, scheduler) and etcd, and then the kubelet is updated via kubeadm upgrade node --kubelet-version, not by directly invoking a package upgrade on the kubelet early. Also, doing this before kubeadm upgrade plan/apply can cause a version skew where the kubelet is newer than the API server, which is explicitly disallowed (kubelet must be at most one minor version behind the apiserver). The correct sequence is to run kubeadm upgrade plan, then kubeadm upgrade apply on the first control plane node, which will handle the kubelet upgrade as part of its process.

About these practice questions

Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.