CKA Troubleshooting Practice Question
You deploy a pod with image 'nginx:1.21'. It stays in ImagePullBackOff. You run 'kubectl describe pod nginx-pod' and see the event: 'Failed to pull image "nginx:1.21": rpc error: code = Unknown desc = Error response from daemon: manifest for nginx:1.21 not found'. What is the most likely fix?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change the image tag to a valid one, e.g., nginx:1.21.6
The tag '1.21' does not exist in the registry. Use a valid tag like '1.21.6' or 'latest'.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a different container runtime
Why it's wrong here
The container runtime (containerd, CRI-O, etc.) is responsible for pulling images, but it will attempt to resolve the exact image tag specified. Since `nginx:1.21` is an invalid tag that does not exist in the Docker Hub registry, any runtime will fail with a manifest unknown error. Switching runtimes does not alter the image reference or registry lookup, so the pull will still fail.
- ✗
Add imagePullSecrets to the pod
Why it's wrong here
imagePullSecrets are used to authenticate to private registries. The nginx image is public on Docker Hub, and the error is not an authentication failure (e.g., 401 or 403) but rather a 'manifest unknown' error indicating the tag itself is invalid. Adding credentials to the pod spec does not change the fact that no image with tag 1.21 exists, so the pull will continue to fail.
- ✗
Restart the kubelet on the node
Why it's wrong here
The kubelet is the component that requests image pulls from the container runtime, but it does not resolve image tags or validate their existence. Restarting the kubelet would only re-trigger the same pull request with the same invalid tag, resulting in the same ImagePullBackOff state. This action is irrelevant to the underlying registry lookup failure.
- ✓
Change the image tag to a valid one, e.g., nginx:1.21.6
Why this is correct
The tag `nginx:1.21` does not exist in the Docker Hub repository; valid tags for the 1.21 series include specific patch versions like `1.21.6`. Changing the image reference to a known valid tag allows the runtime to pull the correct manifest and start the container, resolving the ImagePullBackOff. Always verify available tags in the registry when encountering pull errors.
Go deeper
Related to this question
Key term
kubectl Command Reference
kubectl is the command-line tool used to interact with and manage Kubernetes clusters by sending commands to the Kubernetes API.
Key term
Pod Failure Troubleshooting
Pod failure troubleshooting is the process of identifying and resolving issues that cause Kubernetes pods to crash, restart, or become unavailable.
About these practice questions
Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.