CKA Workloads and Scheduling Practice Question
You have a DaemonSet that is supposed to run on all nodes, but you notice it is not running on a node with a taint 'dedicated=monitoring:NoSchedule'. What must be added to the DaemonSet's pod template to make it run on that node?
⚠ Common exam trap
Many candidates confuse nodeSelector (which selects nodes by labels) with tolerations (which handle taints), leading them to pick option B, but nodeSelector does not override taints.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A toleration with key 'dedicated', value 'monitoring', effect 'NoSchedule'
A DaemonSet's pods must tolerate a node's taints to be scheduled on that node. The taint 'dedicated=monitoring:NoSchedule' means pods without a matching toleration will not be scheduled. Adding a toleration with key 'dedicated', value 'monitoring', and effect 'NoSchedule' explicitly allows the DaemonSet pod to bypass this taint and run on the node.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add the annotation 'scheduler.alpha.kubernetes.io/tolerations'
Why it's wrong here
Using the 'scheduler.alpha.kubernetes.io/tolerations' annotation is a deprecated, pre-v1.6 alpha method for specifying tolerations. In modern Kubernetes clusters, the scheduler ignores this annotation entirely, requiring tolerations to be defined natively within the 'spec.tolerations' field of the Pod template.
- ✗
A nodeSelector with key 'dedicated' and value 'monitoring'
Why it's wrong here
A nodeSelector is used to constrain pods to run only on nodes with matching labels, but it does not bypass or satisfy taints. Even if a node has the label 'dedicated=monitoring', the pod will still be blocked by the 'NoSchedule' taint unless an explicit matching toleration is configured in the pod spec.
- ✗
Set the priorityClassName to 'system-node-critical'
Why it's wrong here
Setting the priorityClassName to 'system-node-critical' ensures the DaemonSet pods are prioritized during scheduling and protected from preemption under resource pressure. However, priority classes do not override scheduling constraints like taints, meaning the scheduler will still refuse to place the pods on tainted nodes.
- ✓
A toleration with key 'dedicated', value 'monitoring', effect 'NoSchedule'
Why this is correct
To allow DaemonSet pods to schedule on nodes carrying the 'dedicated=monitoring:NoSchedule' taint, you must define a matching toleration in the Pod template spec. This toleration explicitly permits the scheduler to place the pods on these tainted nodes, ensuring complete cluster-wide coverage for the DaemonSet.
Go deeper
Related to this question
Learn chapter
Troubleshooting Cluster and Node Issues
Key term
Taints and Tolerations
Taints and tolerations are Kubernetes features that control which pods can be scheduled onto which nodes by marking nodes with a taint and allowing pods to declare a toleration to the taint.
Key term
DaemonSets
A DaemonSet is a Kubernetes object that ensures a copy of a specific pod runs on every node in a cluster, or on a subset of nodes.
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.