CKA Practice Question: Cluster Architecture, Installation and Configuration
Which TWO are true about taints and tolerations? (Select 2)
⚠ Common exam trap
Many candidates confuse which object (node vs. pod) receives taints versus tolerations, leading them to incorrectly select options C or D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A node can have multiple taints
Option B is correct because a Kubernetes node can carry multiple taints simultaneously, each expressed as key=value:effect, and a pod must tolerate every NoSchedule/NoExecute taint on that node to be scheduled there. Option E is correct because tolerations are declared in a pod's spec (spec.tolerations) and let the scheduler place that pod on a node whose taints it matches, effectively overriding the taint's scheduling restriction. Option A is wrong because taints only repel pods that lack matching tolerations, not all pods; pods with appropriate tolerations can still schedule. Option C is wrong because taints are applied to nodes (via kubectl taint nodes), not to pods. Option D is wrong because tolerations are set on pods, not on nodes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Taints prevent all pods from scheduling on a node
Why it's wrong here
A taint only repels pods that do not have a matching toleration. Pods with a toleration that matches the taint's key, value, and effect are allowed to schedule on that node, so taints do not universally block all pods. In fact, the control plane applies taints to nodes to prevent unwanted pods, while tolerated pods can proceed through normal scheduling.
- ✓
A node can have multiple taints
Why this is correct
A node can have multiple taints in its spec.taints list, each defined by a key, value, and effect (NoSchedule, PreferNoSchedule, or NoExecute). For a pod to be schedulable, it must tolerate every taint present on the node; if any taint lacks a matching toleration, the pod will not be scheduled there. This allows fine-grained control over node isolation.
- ✗
Taints are applied to pods
Why it's wrong here
Taints are a property of the Node object, not the Pod object; they are set under spec.taints on nodes. A pod cannot be assigned a taint, but it can carry a toleration in its pod spec that matches node taints. Confusing the two reverses the scheduling mechanism, where nodes repel and pods express tolerance.
- ✗
Tolerations are set on nodes
Why it's wrong here
Tolerations are defined in a Pod's spec.tolerations field, not on nodes. A node carries taints that describe its restrictions, while each pod carries tolerations that declare which taints it can withstand. Setting tolerations on nodes would invert the entire model and has no API support.
- ✓
Tolerations allow pods to schedule on tainted nodes
Why this is correct
A toleration permits a pod to be scheduled onto a node whose taint matches the toleration's key, value, and effect. However, it only permits scheduling, not guarantee it; the pod must also satisfy node selector, affinity rules, and available resources. If a toleration matches, the scheduler ignores that taint when placing the pod.
Go deeper
Related to this question
Learn chapter
Installing Kubernetes with kubeadm
Key term
Taints and Tolerations
Taints and tolerations are Kubernetes features that control which pods can be scheduled onto which nodes by marking nodes with a taint and allowing pods to declare a toleration to the taint.
Key term
kubectl Command Reference
kubectl is the command-line tool used to interact with and manage Kubernetes clusters by sending commands to the Kubernetes API.
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.