CKA Workloads and Scheduling Practice Question
Which TWO taint effects can be used to prevent a pod from being scheduled on a node unless it has a matching toleration?
⚠ Common exam trap
A common mix-up: candidates confuse `PreferNoSchedule` with a hard scheduling constraint, but it only provides a soft preference and does not prevent scheduling, unlike `NoSchedule` and `NoExecute` which are hard constraints.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NoExecute
NoSchedule (C) is correct because it is a taint effect that prevents new pods from being scheduled onto a tainted node unless the pod has a matching toleration; existing pods already running on the node are not evicted. NoExecute (B) is also correct because it not only prevents scheduling of pods without a matching toleration but also evicts already-running pods that do not tolerate the taint, making it a valid taint effect for blocking scheduling. PreferNoSchedule (A) is a soft preference, so the scheduler will try to avoid the node but may still place a pod there without a toleration, so it does not strictly prevent scheduling. FailSchedule (D) and NoAdmit (E) are not valid Kubernetes taint effects; the only supported effects are NoSchedule, PreferNoSchedule, and NoExecute.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PreferNoSchedule
Why it's wrong here
PreferNoSchedule is a valid taint effect, but it is a soft preference rather than a hard restriction. The scheduler will try to avoid placing pods that lack the matching toleration, but it may still schedule them if no other suitable nodes are available. Because it does not definitively prevent scheduling, it cannot be one of the two effects used to keep pods off a node.
- ✓
NoExecute
Why this is correct
NoExecute is one of the two valid taint effects that actively prevent pods from being scheduled on a tainted node. In addition to preventing new pods without the toleration from landing there, it also evicts any existing pods on the node that do not tolerate the taint. This makes NoExecute the most aggressive effect, as it immediately removes running workloads, unlike NoSchedule which only blocks future scheduling.
- ✓
NoSchedule
Why this is correct
NoSchedule is the other valid taint effect that prevents pods from being scheduled on a tainted node. When a node has a taint with the NoSchedule effect, the scheduler will not place any pod that does not have a matching toleration onto that node. Unlike NoExecute, it does not evict pods that are already running on the node, so it creates a hard scheduling barrier without disrupting existing workloads.
- ✗
FailSchedule
Why it's wrong here
FailSchedule is not a recognized taint effect in Kubernetes. The only taint effects defined by the Kubernetes API are NoSchedule, PreferNoSchedule, and NoExecute. Using FailSchedule in a taint definition would result in an invalid value and the API server would reject it, so it has no effect on pod scheduling whatsoever.
- ✗
NoAdmit
Why it's wrong here
NoAdmit is not a real taint effect; it appears to be a confusion with admission control mechanisms such as the PodTolerationRestriction admission controller. Taint effects are specifically defined in the core Kubernetes API and are limited to NoSchedule, PreferNoSchedule, and NoExecute. NoAdmit has no meaning to the scheduler and cannot be used to prevent pod placement.
Go deeper
Related to this question
Learn chapter
Troubleshooting Cluster and Node Issues
Key term
Taints and Tolerations
Taints and tolerations are Kubernetes features that control which pods can be scheduled onto which nodes by marking nodes with a taint and allowing pods to declare a toleration to the taint.
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
About these practice questions
Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.