CKA Practice Question: Cluster Architecture, Installation and Configuration
Which kubectl command is used to mark a node as unschedulable for new pods without affecting existing running pods?
⚠ Common exam trap
Watch out — candidates often confuse `kubectl drain` (which evicts pods and then cordons) with `kubectl cordon` (which only prevents new scheduling), leading them to select drain when the question explicitly states 'without affecting existing running pods'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl cordon <node-name>
The `kubectl cordon` command marks a node as unschedulable by setting the `node.Spec.Unschedulable` field to `true`. This prevents the Kubernetes scheduler from placing new pods onto the node, while existing pods continue to run unaffected. It is the correct tool for this specific maintenance task.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
kubectl cordon <node-name>
Why this is correct
This command directly sets the .spec.unschedulable field of the specified Node object to true. This prevents the Kubernetes scheduler from assigning any new pods to the node, while leaving existing running pods completely unaffected. It is the most direct and lightweight way to temporarily halt scheduling on a specific node.
- ✗
kubectl uncordon <node-name>
Why it's wrong here
This command performs the exact opposite action by setting the Node's .spec.unschedulable field back to false. It allows the scheduler to resume placing new workloads onto the node. While related to node scheduling state, it is used to restore schedulability rather than marking a node as unschedulable.
- ✗
kubectl drain <node-name>
Why it's wrong here
While this command does implicitly cordon the node first, its primary purpose is to safely evict or delete all running pods from the node so it can be taken down for maintenance. Using this command goes beyond simply marking a node as unschedulable, as it actively disrupts and migrates existing workloads, which may not be the desired outcome.
- ✗
kubectl taint nodes <node-name> key=value:NoSchedule
Why it's wrong here
Applying a NoSchedule taint prevents pods from being scheduled on the node unless they possess a matching toleration. This does not strictly mark the node as globally unschedulable, because pods with the correct toleration can still be scheduled there. In contrast, cordoning a node is an absolute restriction that applies to all pods regardless of their tolerations.
Go deeper
Related to this question
Learn chapter
Kubernetes Architecture Overview
Key term
kubectl Command Reference
kubectl is the command-line tool used to interact with and manage Kubernetes clusters by sending commands to the Kubernetes API.
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.