Courseiva

CKA · topic practice

Cluster Architecture, Installation & Configuration practice questions

This domain covers bootstrapping and maintaining Kubernetes control planes and nodes with kubeadm, plus static pod manifests, kubelet configuration, certificates, and cluster upgrades. CKA tasks here are hands-on: you run kubeadm commands, inspect kubelet and container runtime state, edit manifests under /etc/kubernetes/manifests, and repair broken control plane or node components.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Cluster Architecture, Installation & Configuration

What the exam tests

What to know about Cluster Architecture, Installation & Configuration

Be able to bootstrap a cluster with kubeadm, join nodes, and repair a NotReady control plane by reading kubelet logs and static pod manifests. The single most important thing: after any manifest or config change, verify the component actually restarted and the node returns to Ready.

Running kubeadm init, kubeadm join, and kubeadm token create --print-join-command for cluster membership

Inspecting kubelet health with systemctl status kubelet and journalctl -u kubelet for startup failures

Managing static pods in /etc/kubernetes/manifests for kube-apiserver, kube-controller-manager, kube-scheduler, and etcd

Performing kubeadm upgrade plan and kubeadm upgrade apply, then draining and upgrading nodes

Watch out for

Common Cluster Architecture, Installation & Configuration exam traps

  • ▸Re-running kubeadm init on a dirty host without kubeadm reset, leaving stale certificates, etcd data, or CNI config that breaks the new control plane.
  • ▸Editing static pod manifests directly but forgetting the kubelet restarts them automatically, so changes must be valid YAML or the component crash-loops.
  • ▸Confusing kubelet service failures with container runtime failures; checking only kubectl output instead of journalctl and crictl to find the real cause.

Practice set

Cluster Architecture, Installation & Configuration questions

20 questions · select your answer, then reveal the explanation

A company wants to install Kubernetes on a set of bare-metal servers with no existing orchestration tools. They need a solution that supports high availability for the control plane and uses etcd operators for cluster management. Which tool should they use?

An administrator needs to upgrade the kube-apiserver on a control plane node from version 1.22.0 to 1.23.0. Which of the following is the correct order of steps?

A cluster administrator has configured a PodSecurityPolicy (PSP) that requires all pods to run with read-only root filesystem. However, a newly deployed pod is failing to start with the error 'container has runAsNonRoot and image will run as root'. The PSP is designed to prevent running as root. What is the most likely cause?

A cluster is running on a cloud provider that supports load balancers. An administrator needs to expose a service externally using a cloud load balancer. However, the service remains in 'Pending' state. The cloud provider requires the cluster to be configured with the correct cloud provider flag. Which kube-controller-manager flag is required for this integration?

Which TWO of the following are valid commands to upgrade a kubeadm cluster from version 1.22.x to 1.23.x on the control plane node? Assume the node is already drained.

A cluster uses etcd with TLS encryption. Which THREE of the following are valid etcd client certificate authentication flags?

Which TWO of the following are valid methods to configure the kubelet's node IP address?

Which THREE of the following are valid steps to enable audit logging in a Kubernetes cluster?

Which TWO of the following are valid methods to add a worker node to an existing Kubernetes cluster that was initialized with kubeadm?

Based on the exhibit, what is the most likely cause of the worker2 node being NotReady?

Exhibit

Refer to the exhibit.
```
$ kubectl get nodes
NAME           STATUS   ROLES    AGE   VERSION
controlplane   Ready    master   10d   v1.25.0
worker1        Ready    <none>   10d   v1.25.0
worker2        NotReady <none>   10d   v1.25.0

$ kubectl describe node worker2 | grep -i condition
Conditions:
  Type                 Status  LastHeartbeatTime                 LastTransitionTime                Reason                       Message
  ----                 ------  -----------------                 ------------------                ------                       -------
  NetworkUnavailable   False   Thu, 01 Jan 2023 00:00:00 +0000   Thu, 01 Jan 2023 00:00:00 +0000   CalicoIsUp                   Calico is running on this node
  MemoryPressure       False   Thu, 01 Jan 2023 00:00:00 +0000   Thu, 01 Jan 2023 00:00:00 +0000   KubeletHasSufficientMemory   kubelet has sufficient memory available
  DiskPressure         False   Thu, 01 Jan 2023 00:00:00 +0000   Thu, 01 Jan 2023 00:00:00 +0000   KubeletHasNoDiskPressure     kubelet has no disk pressure
  PIDPressure          False   Thu, 01 Jan 2023 00:00:00 +0000   Thu, 01 Jan 2023 00:00:00 +0000   KubeletHasSufficientPID      kubelet has sufficient PID available
  Ready                Unknown Thu, 01 Jan 2023 00:00:00 +0000   Thu, 01 Jan 2023 00:00:00 +0000   NodeStatusUnknown            Kubelet stopped posting node status.
```

You are tasked with upgrading a Kubernetes cluster from version 1.24 to 1.25. The cluster has one control plane node and three worker nodes, all running Ubuntu 20.04 with kubeadm. You have already upgraded the control plane node to v1.25.0 and it is healthy. You now need to upgrade the first worker node. On the worker node, you run 'kubeadm upgrade node' and it completes successfully. However, when you run 'kubectl drain worker1 --ignore-daemonsets', the node drain hangs indefinitely. You check the node and find that a DaemonSet pod named 'fluentd-*' is stuck in Terminating state. The DaemonSet is from the logging system and must remain running during the upgrade. You cannot delete the DaemonSet. What is the best course of action to complete the upgrade of this worker node?

Drag and drop the steps to create a Kubernetes cluster using kubeadm into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Drag and drop the steps to deploy an application using a Deployment and expose it with a Service into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Match each Kubernetes resource to its primary function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Smallest deployable unit, runs containers

Stable network endpoint for a set of Pods

HTTP/HTTPS routing to Services

Non-sensitive configuration data

Storage resource provisioned by an administrator

Match each security context setting to its effect.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Specifies the user ID for the container's process

Prevents running as root (UID 0)

Grants elevated privileges to the container

Makes the container's root filesystem read-only

Adds or drops Linux capabilities

Refer to the exhibit. A pod named nginx-pod is stuck in Pending state. Based on the describe output, what is the most likely cause?

Exhibit

```
$ kubectl get nodes
NAME     STATUS   ROLES                  AGE   VERSION
master   Ready    control-plane,master   10d   v1.28.0
node1    Ready    <none>                 10d   v1.28.0
node2    Ready    <none>                 10d   v1.28.0
node3    Ready    <none>                 10d   v1.28.0

$ kubectl describe pod nginx-pod
Name:         nginx-pod
Namespace:    default
Priority:     0
Node:         node1/192.168.1.101
Start Time:   Mon, 01 Jan 2024 12:00:00 +0000
Labels:       run=nginx
Annotations:  <none>
Status:       Pending
IP:           
IPs:          <none>
Events:
  Type     Reason            Age   From               Message
  ----     ------            ----  ----               -------
  Warning  FailedScheduling  2m    default-scheduler  0/4 nodes are available: 1 node(s) had untolerated taint {node.kubernetes.io/not-ready: }, 3 node(s) had untolerated taint {node.kubernetes.io/unreachable: }. preemption: 0/4 nodes are available: 4 Preemption is not helpful for scheduling.
```

Refer to the exhibit. An etcd pod on the master node shows repeated rejected connections from node2 (192.168.1.102) and node3 (192.168.1.103). The error indicates non-TLS traffic. What is the most likely cause?

Exhibit

```
$ kubectl get pods -n kube-system | grep etcd
etcd-master                1/1     Running   0          10d

$ kubectl logs -n kube-system etcd-master | tail -5
2024-01-01 12:00:00.000000 I | embed: rejected connection from "192.168.1.102:45678" (error "tls: first record does not look like a TLS handshake", ServerName "")
2024-01-01 12:00:01.000000 I | embed: rejected connection from "192.168.1.103:45678" (error "tls: first record does not look like a TLS handshake", ServerName "")
2024-01-01 12:00:02.000000 I | embed: rejected connection from "192.168.1.102:45679" (error "tls: first record does not look like a TLS handshake", ServerName "")

$ kubectl get nodes -o wide
NAME     STATUS   ROLES                  AGE   VERSION   INTERNAL-IP     EXTERNAL-IP
master   Ready    control-plane,master   10d   v1.28.0   192.168.1.100   <none>
node1    Ready    <none>                 10d   v1.28.0   192.168.1.101   <none>
node2    Ready    <none>                 10d   v1.28.0   192.168.1.102   <none>
node3    Ready    <none>                 10d   v1.28.0   192.168.1.103   <none>
```

Refer to the exhibit. An administrator notices that kube-proxy on worker3 is in CrashLoopBackOff. What is the most likely cause?

Exhibit

$ kubectl get nodes
NAME           STATUS   ROLES    AGE   VERSION
controlplane   Ready    master   45d   v1.28.2
worker1        Ready    <none>   45d   v1.28.2
worker2        Ready    <none>   45d   v1.28.2
worker3        Ready    <none>   45d   v1.29.0
$ kubectl get pods -n kube-system | grep kube-proxy
kube-proxy-controlplane   1/1     Running   0   45d
kube-proxy-worker1        1/1     Running   0   45d
kube-proxy-worker2        1/1     Running   0   45d
kube-proxy-worker3        0/1     CrashLoopBackOff   3   1m

Refer to the exhibit. After initializing the cluster with this configuration, a user runs 'kubectl get nodes -L topology.kubernetes.io/zone' and the label is not shown. What is the most likely reason?

Exhibit

apiVersion: kubeadm.k8s.io/v1beta3
kind: InitConfiguration
nodeRegistration:
  kubeletExtraArgs:
    node-labels: "topology.kubernetes.io/zone=us-east-1a"
---
apiVersion: kubeadm.k8s.io/v1beta3
kind: ClusterConfiguration
networking:
  podSubnet: "10.244.0.0/16"
  serviceSubnet: "10.96.0.0/12"

Refer to the exhibit. A user tries to schedule an additional pod with memory request 256Mi and limit 512Mi on worker1, but it remains Pending. What is the most likely reason?

Exhibit

apiVersion: v1
kind: Pod
metadata:
  name: nginx
spec:
  containers:
  - name: nginx
    image: nginx:1.21
    resources:
      limits:
        memory: "256Mi"
        cpu: "500m"
      requests:
        memory: "128Mi"
        cpu: "250m"
  priorityClassName: high-priority
---
apiVersion: scheduling.k8s.io/v1
kind: PriorityClass
metadata:
  name: high-priority
value: 1000000
globalDefault: false
description: "High priority class"
---
$ kubectl describe node worker1 | grep -A5 "Allocated resources"
  Allocated resources:
    (Total limits may be over 100 percent, i.e., overcommitted.)
    Resource           Requests     Limits
    --------           --------     ------
    cpu                1000m (50%)  2000m (100%)
    memory             512Mi (25%)  1Gi (50%)
  Non-terminated Pods:          (3 in total)
  Namespace                   Name                CPU Requests  CPU Limits  Memory Requests  Memory Limits
  default                     nginx               250m (12%)     500m (25%)  128Mi (6%)       256Mi (12%)
  default                     app                 500m (25%)     1 (50%)     256Mi (12%)      512Mi (25%)
  kube-system                 fluentd             250m (12%)     500m (25%)  128Mi (6%)       256Mi (12%)
  Taints: node.kubernetes.io/unschedulable:NoSchedule

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Cluster Architecture, Installation & Configuration sessions

Start a Cluster Architecture, Installation & Configuration only practice session

Every question in these sessions is drawn from the Cluster Architecture, Installation & Configuration domain — nothing else.

Related practice questions

Related CKA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CKA exam test about Cluster Architecture, Installation & Configuration?
Be able to bootstrap a cluster with kubeadm, join nodes, and repair a NotReady control plane by reading kubelet logs and static pod manifests. The single most important thing: after any manifest or config change, verify the component actually restarted and the node returns to Ready.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Cluster Architecture, Installation & Configuration questions in a focused session?
Yes — the session launcher on this page draws every question from the Cluster Architecture, Installation & Configuration domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CKA topics?
Use the topic links above to move to related areas, or go back to the CKA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CKA exam covers. They are not copied from any real exam or dump site.