CKA Workloads and Scheduling Practice Question
You have a DaemonSet that runs on all nodes. You need to ensure it does NOT run on a node labeled 'disk=ssd'. Which field in the DaemonSet spec should you use?
⚠ Common exam trap
Many candidates confuse `nodeSelector` (which selects nodes to include) with the need to exclude nodes, and they may incorrectly choose `nodeSelector` with a negative label value, not realizing that `nodeSelector` only supports equality-based inclusion, not exclusion.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
spec.template.spec.affinity.nodeAffinity.requiredDuringSchedulingIgnoredDuringExecution with NotIn operator
`nodeAffinity.requiredDuringSchedulingIgnoredDuringExecution` with the `NotIn` operator allows you to specify that the DaemonSet pod must not be scheduled on nodes with the label `disk=ssd`. This is the proper way to express an anti-affinity rule that excludes nodes based on a label value, ensuring the DaemonSet runs on all nodes except those with `disk=ssd`.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
spec.template.spec.affinity.nodeAffinity.requiredDuringSchedulingIgnoredDuringExecution with NotIn operator
Why this is correct
Using nodeAffinity with the requiredDuringSchedulingIgnoredDuringExecution field enforces a hard scheduling constraint. By specifying the NotIn operator with the key disk and value ssd, the Kubernetes scheduler is strictly prohibited from placing the DaemonSet pods on any node labeled with disk=ssd, effectively excluding them while allowing scheduling on all other nodes.
- ✗
spec.template.spec.nodeSelector with disk: ssd
Why it's wrong here
Configuring a nodeSelector with disk: ssd acts as a positive selection filter, forcing the DaemonSet pods to run only on nodes that possess this exact label. This directly contradicts the goal of avoiding these nodes, resulting in pods being scheduled exclusively on SSD-backed nodes instead of excluding them.
- ✗
spec.template.spec.tolerations with key disk value ssd
Why it's wrong here
Tolerations are designed to allow pods to schedule on nodes with matching taints, but they do not actively steer pods toward or away from nodes based on standard node labels. Applying a toleration for disk=ssd would only permit scheduling if the node had a corresponding taint, failing to prevent scheduling on nodes that simply have the disk=ssd label.
- ✗
spec.updateStrategy.rollingUpdate.maxUnavailable
Why it's wrong here
The maxUnavailable parameter is a sub-field of the DaemonSet's update strategy used to control how many pods can be offline simultaneously during a rolling update. It has no influence over initial pod scheduling decisions, node selection, or label-based filtering of target nodes.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.