CKA Practice Question: Cluster Architecture, Installation and Configuration
Which kubectl command is used to mark a node as unschedulable so that no new pods are scheduled onto it?
⚠ Common exam trap
It's easy for candidates to confuse `cordon` with `drain`—candidates often pick `drain` because they think it makes the node unschedulable, but `drain` additionally evicts all pods, which is not what the question asks for.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl cordon <node>
The `kubectl cordon <node>` command marks a node as unschedulable by setting the `node.Spec.Unschedulable` field to `true`. This prevents the Kubernetes scheduler from placing any new pods onto that node, while existing pods continue to run unaffected. This is the correct command for the described task.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl taint <node>
Why it's wrong here
While the kubectl taint command applies a key-value effect to a node that repels pods unless they have matching tolerations, it does not explicitly set the node's spec.unschedulable field to true. Pods with the appropriate tolerations can still be scheduled on a tainted node, meaning the node remains technically schedulable.
- ✗
kubectl uncordon <node>
Why it's wrong here
The kubectl uncordon command performs the exact opposite action of what is requested by setting the node's spec.unschedulable field to false. This action allows the Kubernetes scheduler to resume placing new workloads on the node, making it active and schedulable again.
- ✗
kubectl drain <node>
Why it's wrong here
Although kubectl drain cordons a node as part of its execution, its primary purpose is to safely evict or delete all running pods on that node to prepare it for maintenance. Using this command is overly disruptive if the goal is solely to prevent new scheduling without disturbing existing workloads.
- ✓
kubectl cordon <node>
Why this is correct
The kubectl cordon command is the precise administrative tool used to toggle a node's status to unschedulable by updating its spec.unschedulable field to true. This action prevents the scheduler from assigning any new pods to the node while safely leaving existing, currently running workloads completely unaffected.
Go deeper
Related to this question
Learn chapter
Kubernetes Architecture Overview
Key term
kubectl Command Reference
kubectl is the command-line tool used to interact with and manage Kubernetes clusters by sending commands to the Kubernetes API.
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.