CKA Practice Question: Cluster Architecture, Installation & Configuration
During a 'kubeadm init', the administrator sees the message 'Your Kubernetes control-plane has been initialized successfully!' but the 'kubectl get nodes' shows the control plane node as 'NotReady'. What is the most likely missing step?
⚠ Common exam trap
It's easy for candidates to assume 'kubeadm init' success means the cluster is fully functional, but they overlook the mandatory post-init step of installing a CNI plugin to make the node 'Ready'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Install a CNI plugin such as Calico or Flannel.
The 'NotReady' status indicates that the kubelet on the control plane node is running but cannot report readiness because the node's network is not configured. A CNI plugin (e.g., Calico, Flannel, Weave) must be installed to set up the pod network, which is required for the kubelet to register the node as 'Ready'. Without a CNI plugin, the node's network conditions remain unmet, and the control plane cannot function properly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Generate a join token for worker nodes.
Why it's wrong here
Generating a bootstrap token via kubeadm is used exclusively to authenticate and register new worker nodes to the control plane. It does not resolve the pending network configuration of the control plane node itself, which is required before any workloads or worker nodes can successfully communicate.
- ✓
Install a CNI plugin such as Calico or Flannel.
Why this is correct
Kubernetes requires a Container Network Interface (CNI) plugin to establish the pod network. Until a CNI provider like Calico or Flannel is deployed, CoreDNS pods will remain in a Pending state, and the control plane node will report a status of NotReady due to the missing network configuration.
- ✗
Copy the kubeconfig to the user's home directory.
Why it's wrong here
Copying the admin.conf file to the user's home directory is a post-initialization step that configures administrative access for the kubectl CLI tool. While necessary for cluster management, this action only affects client-side authentication and has no impact on the operational readiness of the node or the underlying cluster networking.
- ✗
Check that the kubelet is running on the control plane node.
Why it's wrong here
The kubelet daemon must already be running successfully for kubeadm init to complete its initial control plane bootstrapping phases. If the node is marked NotReady, it indicates that the kubelet is active but reporting a network plugin uninitialized error, rather than the service being stopped.
Go deeper
Related to this question
Learn chapter
Kubernetes Architecture Overview
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
kubectl Command Reference
kubectl is the command-line tool used to interact with and manage Kubernetes clusters by sending commands to the Kubernetes API.
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.