Courseiva
Troubleshooting →mediumMultiple Choice

CKA Troubleshooting Practice Question

You deploy a pod with image 'nginx:1.21'. It stays in ImagePullBackOff. You run 'kubectl describe pod nginx-pod' and see the event: 'Failed to pull image "nginx:1.21": rpc error: code = Unknown desc = Error response from daemon: manifest for nginx:1.21 not found'. What is the most likely fix?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change the image tag to a valid one, e.g., nginx:1.21.6

The tag '1.21' does not exist in the registry. Use a valid tag like '1.21.6' or 'latest'.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a different container runtime

    Why it's wrong here

    The container runtime (containerd, CRI-O, etc.) is responsible for pulling images, but it will attempt to resolve the exact image tag specified. Since `nginx:1.21` is an invalid tag that does not exist in the Docker Hub registry, any runtime will fail with a manifest unknown error. Switching runtimes does not alter the image reference or registry lookup, so the pull will still fail.

  • ✗

    Add imagePullSecrets to the pod

    Why it's wrong here

    imagePullSecrets are used to authenticate to private registries. The nginx image is public on Docker Hub, and the error is not an authentication failure (e.g., 401 or 403) but rather a 'manifest unknown' error indicating the tag itself is invalid. Adding credentials to the pod spec does not change the fact that no image with tag 1.21 exists, so the pull will continue to fail.

  • ✗

    Restart the kubelet on the node

    Why it's wrong here

    The kubelet is the component that requests image pulls from the container runtime, but it does not resolve image tags or validate their existence. Restarting the kubelet would only re-trigger the same pull request with the same invalid tag, resulting in the same ImagePullBackOff state. This action is irrelevant to the underlying registry lookup failure.

  • ✓

    Change the image tag to a valid one, e.g., nginx:1.21.6

    Why this is correct

    The tag `nginx:1.21` does not exist in the Docker Hub repository; valid tags for the 1.21 series include specific patch versions like `1.21.6`. Changing the image reference to a known valid tag allows the runtime to pull the correct manifest and start the container, resolving the ImagePullBackOff. Always verify available tags in the registry when encountering pull errors.

About these practice questions

Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.