CKA Practice Question: Cluster Architecture, Installation and Configuration
During a cluster upgrade, what is the correct order of operations for upgrading a node?
⚠ Common exam trap
Test-takers frequently think uncordoning can be done before upgrading (options B and D) or that upgrading can precede draining (option A), but the CKA requires strict adherence to the drain-upgrade-uncordon sequence to maintain workload availability and version compatibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Drain the node, upgrade kubelet and kube-proxy, then uncordon
During a node upgrade, the node must first be drained to safely evict all pods and ensure workloads are rescheduled. Then, the kubelet and kube-proxy (which run as system services) are upgraded to match the control plane version. Finally, the node is uncordoned to make it schedulable again, allowing new pods to be placed on it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Upgrade kubelet, drain the node, then uncordon
Why it's wrong here
Upgrading the kubelet while active workloads are running on the node can lead to unexpected pod termination, state inconsistency, or application downtime. To prevent service disruption, you must safely evict and reschedule pods by draining the node before initiating any package upgrades. Only after the node is cleared of workloads should the kubelet binary be updated.
- ✗
Drain the node, uncordon, then upgrade kubelet
Why it's wrong here
Uncordoning the node immediately after draining it allows the Kubernetes scheduler to assign new pods to this node before the upgrade occurs. This exposes active workloads to potential disruption when the kubelet service is subsequently restarted during the upgrade process. The node must remain cordoned until the kubelet and kube-proxy upgrades are fully completed and verified.
- ✓
Drain the node, upgrade kubelet and kube-proxy, then uncordon
Why this is correct
This sequence represents the official Kubernetes standard operating procedure for node upgrades to ensure zero-downtime. Draining safely evicts running pods to other nodes, upgrading the kubelet and kube-proxy updates the node's control plane components while idle, and uncordoning finally marks the upgraded node as schedulable again. This minimizes service disruption and maintains cluster stability.
- ✗
Uncordon the node, drain, then upgrade
Why it's wrong here
Uncordoning a node that is already schedulable has no beneficial effect, and attempting to drain it immediately afterward defeats the purpose of scheduling new workloads. This incorrect sequence risks scheduling new pods onto a node that is about to be disrupted by the drain and upgrade process. The uncordon step must always be the final action performed after all upgrades are complete.
Go deeper
Related to this question
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.