CKA Practice Question: Cluster Architecture, Installation and Configuration
You are setting up a new Kubernetes cluster using kubeadm. You run 'kubeadm init --pod-network-cidr=10.244.0.0/16' on the control plane node. The command fails with: '[preflight] Some fatal errors occurred: [ERROR CRI]: container runtime is not running: output: time="..." level=fatal msg="validate service connection: CRI v1 runtime API is not implemented for endpoint 'unix:///var/run/containerd/containerd.sock': rpc error: code = Unimplemented desc = unknown service runtime.v1.RuntimeService'"'. What is the most likely cause?
⚠ Common exam trap
It's easy for candidates to assume the error means the container runtime is not running at all (Option D), but the detailed error message clearly indicates the socket is reachable and the issue is an API version mismatch, not a service outage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The containerd runtime does not support the CRI v1 API; it may be an older version that only supports v1alpha2
The error message indicates that the containerd socket is reachable but the CRI v1 API (runtime.v1.RuntimeService) is not implemented. This typically occurs when containerd is an older version that only supports the CRI v1alpha2 API. Kubernetes 1.24+ defaults to the CRI v1 API, so an older containerd without v1 support will fail during kubeadm init.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The --pod-network-cidr flag is incorrect
Why it's wrong here
The --pod-network-cidr flag is used during kubeadm init to allocate IP ranges for the pod network add-on, which is a post-initialization networking concern. It has no bearing on the low-level Container Runtime Interface (CRI) handshake between the kubelet and the container runtime. A mismatch or failure during the CRI API negotiation points directly to runtime configuration issues, not cluster IP allocation settings.
- ✗
The kubelet version is incompatible with containerd
Why it's wrong here
While the kubelet and containerd must be compatible, the specific error stems from a mismatch in the supported CRI API versions rather than a general binary incompatibility of the kubelet itself. Modern kubelet versions are designed to work with containerd, provided the runtime is configured to expose the correct CRI version. Upgrading or downgrading the kubelet will not resolve the issue if the underlying runtime is still serving an outdated API version.
- ✓
The containerd runtime does not support the CRI v1 API; it may be an older version that only supports v1alpha2
Why this is correct
Modern Kubernetes releases require the Container Runtime Interface (CRI) v1 API to communicate with the container runtime. Older versions of containerd (prior to v1.6.0) only implement the deprecated v1alpha2 CRI API, causing the kubelet's initialization handshake to fail when it attempts to connect. Upgrading containerd to v1.6.0 or later, or correctly configuring its CRI plugin, is required to enable v1 API support.
- ✗
The containerd service is not running
Why it's wrong here
If the containerd systemd service were completely stopped or disabled, the kubelet would fail immediately with a connection refused or missing socket file error when attempting to access the gRPC socket. Because the socket is responsive but returns an unimplemented error for the v1 API, we know the daemon is running and actively listening. The failure is purely a protocol negotiation issue, not an offline service.
Visual reference
Go deeper
Related to this question
Learn chapter
Installing Kubernetes with kubeadm
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
Kubernetes Node Roles
Kubernetes Node Roles are labels assigned to machines in a cluster that define whether a node runs application containers (worker) or manages the cluster (control plane).
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.