Courseiva

CKA Practice Question: Cluster Architecture, Installation and Configuration

You are troubleshooting a pod that is in 'Pending' state. Running 'kubectl describe pod' shows the event: '0/3 nodes are available: 3 node(s) had taint {node-role.kubernetes.io/master: }, that the pod didn't tolerate.' What is the most likely cause?

⚠ Common exam trap

Watch out — candidates often confuse taints/tolerations with node selectors or resource constraints, but the event message directly identifies the taint as the cause, making D the only correct answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The pod is trying to schedule on the master node which has a taint that is not tolerated

The pod is in 'Pending' state because none of the three nodes are schedulable for it. The 'kubectl describe pod' event explicitly states that all three nodes have the taint 'node-role.kubernetes.io/master: ' and the pod does not have a corresponding toleration. Master nodes are typically tainted to prevent general workloads from scheduling on them, so a pod without a toleration for that taint cannot be placed on any master node, leaving zero available nodes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The pod requires more CPU than any node can provide

    Why it's wrong here

    If a pod remains pending due to insufficient CPU, the scheduler emits a FailedScheduling event with a message like '0/N nodes are available: N Insufficient cpu.' Because the diagnostic event specifically points to an untolerated taint, resource starvation is not the root cause of this scheduling failure.

  • ✗

    The pod is using a hostPort that conflicts with another pod

    Why it's wrong here

    A hostPort conflict occurs when a pod requests a specific port on the host network that is already bound by an active pod on that node. The Kubernetes scheduler would flag this with a 'node(s) didn't have free ports' event rather than a taint mismatch error, making this explanation incorrect for the observed taint event.

  • ✗

    The pod has a node selector that doesn't match any node

    Why it's wrong here

    When a pod's nodeSelector or nodeAffinity rules cannot be satisfied by any active node in the cluster, the scheduler reports a 'node(s) didn't match PodTemplate Cohort/NodeSelector' event. This is distinct from taint-related scheduling rejections, which occur when a node's taints lack corresponding tolerations in the pod spec.

  • ✓

    The pod is trying to schedule on the master node which has a taint that is not tolerated

    Why this is correct

    Control plane nodes are typically configured with a default taint, such as node-role.kubernetes.io/control-plane:NoSchedule, to prevent user workloads from consuming critical system resources. For a pod to successfully schedule onto such a node, its specification must explicitly define a matching toleration, otherwise, it remains in a Pending state with a taint-related scheduling event.

About these practice questions

Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.