Courseiva
Workloads and Scheduling →mediumMultiple Select

CKA Workloads and Scheduling Practice Question

Which TWO taint effects can be used to prevent a pod from being scheduled on a node unless it has a matching toleration?

⚠ Common exam trap

A common mix-up: candidates confuse `PreferNoSchedule` with a hard scheduling constraint, but it only provides a soft preference and does not prevent scheduling, unlike `NoSchedule` and `NoExecute` which are hard constraints.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NoExecute

NoSchedule (C) is correct because it is a taint effect that prevents new pods from being scheduled onto a tainted node unless the pod has a matching toleration; existing pods already running on the node are not evicted. NoExecute (B) is also correct because it not only prevents scheduling of pods without a matching toleration but also evicts already-running pods that do not tolerate the taint, making it a valid taint effect for blocking scheduling. PreferNoSchedule (A) is a soft preference, so the scheduler will try to avoid the node but may still place a pod there without a toleration, so it does not strictly prevent scheduling. FailSchedule (D) and NoAdmit (E) are not valid Kubernetes taint effects; the only supported effects are NoSchedule, PreferNoSchedule, and NoExecute.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PreferNoSchedule

    Why it's wrong here

    PreferNoSchedule is a valid taint effect, but it is a soft preference rather than a hard restriction. The scheduler will try to avoid placing pods that lack the matching toleration, but it may still schedule them if no other suitable nodes are available. Because it does not definitively prevent scheduling, it cannot be one of the two effects used to keep pods off a node.

  • ✓

    NoExecute

    Why this is correct

    NoExecute is one of the two valid taint effects that actively prevent pods from being scheduled on a tainted node. In addition to preventing new pods without the toleration from landing there, it also evicts any existing pods on the node that do not tolerate the taint. This makes NoExecute the most aggressive effect, as it immediately removes running workloads, unlike NoSchedule which only blocks future scheduling.

  • ✓

    NoSchedule

    Why this is correct

    NoSchedule is the other valid taint effect that prevents pods from being scheduled on a tainted node. When a node has a taint with the NoSchedule effect, the scheduler will not place any pod that does not have a matching toleration onto that node. Unlike NoExecute, it does not evict pods that are already running on the node, so it creates a hard scheduling barrier without disrupting existing workloads.

  • ✗

    FailSchedule

    Why it's wrong here

    FailSchedule is not a recognized taint effect in Kubernetes. The only taint effects defined by the Kubernetes API are NoSchedule, PreferNoSchedule, and NoExecute. Using FailSchedule in a taint definition would result in an invalid value and the API server would reject it, so it has no effect on pod scheduling whatsoever.

  • ✗

    NoAdmit

    Why it's wrong here

    NoAdmit is not a real taint effect; it appears to be a confusion with admission control mechanisms such as the PodTolerationRestriction admission controller. Taint effects are specifically defined in the core Kubernetes API and are limited to NoSchedule, PreferNoSchedule, and NoExecute. NoAdmit has no meaning to the scheduler and cannot be used to prevent pod placement.

About these practice questions

Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.