CKA Practice Question: Cluster Architecture, Installation and Configuration
Which command is used to create a backup of etcd data using etcdctl?
⚠ Common exam trap
Many exam-takers confuse the `save` and `restore` subcommands, often selecting `snapshot restore` (Option B) because they think 'backup' implies 'restore', but `save` is the correct verb for creating a backup.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
etcdctl snapshot save /backup/snapshot.db
`etcdctl snapshot save` is the command used to create a point-in-time backup of etcd data. This command captures the entire key-value store and writes it to a specified file path, which is essential for disaster recovery in Kubernetes clusters that use etcd as their backing store.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
etcdctl endpoint status
Why it's wrong here
This command is used to query the current health, database size, raft index, and leadership status of the specified etcd cluster endpoints. It does not perform any data serialization or backup operations. To use it effectively, administrators typically combine it with the write-out flag to inspect cluster health.
- ✗
etcdctl snapshot restore /backup/snapshot.db
Why it's wrong here
This command is used during disaster recovery to initialize a new etcd data directory from an existing backup file. It is a destructive operation that should only be run when bootstrapping a new cluster or recovering a failed one, rather than generating a new backup file from a running cluster.
- ✓
etcdctl snapshot save /backup/snapshot.db
Why this is correct
This is the correct command to capture a point-in-time backup of the active etcd keyspace and write it to a specified file path. When executed with the appropriate TLS certificates and endpoints, it securely streams the database state into a single compressed snapshot file suitable for disaster recovery.
- ✗
etcdctl member list
Why it's wrong here
This command queries the etcd cluster to output a list of all active peer members, including their IDs, names, peer URLs, and client URLs. While useful for verifying cluster membership and quorum status, it does not interact with the underlying database storage engine to generate or export backup files.
Go deeper
Related to this question
Learn chapter
Kubernetes Architecture Overview
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
About these practice questions
Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.