Courseiva
Troubleshooting →mediumMultiple Choice

CKA Troubleshooting Practice Question

You have a Deployment with 3 replicas. After updating the container image, the new pods are in 'ImagePullBackOff' state. You run 'kubectl describe pod <pod-name>' and see the event: 'Failed to pull image "myregistry/myapp:latest": rpc error: code = Unknown desc = Error response from daemon: manifest for myregistry/myapp:latest not found: manifest unknown: manifest unknown'. What is the MOST likely cause?

⚠ Common exam trap

Kubernetes often tests the distinction between registry reachability errors and image existence errors, where candidates mistakenly assume network or authentication issues when the actual problem is a missing tag in the registry.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The image tag 'latest' does not exist in the registry

The error message 'manifest unknown' indicates that the registry successfully reached but the specific image tag 'latest' does not exist in the repository. This is a registry-side error, not a network or authentication issue. The container runtime can communicate with the registry but cannot find the manifest for the requested tag.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The registry is unreachable from the nodes

    Why it's wrong here

    If the container runtime on the worker nodes could not establish a network connection to the container registry, the kubelet would report a connection timeout, DNS resolution failure, or connection refused error. Instead, receiving a "manifest not found" error confirms that a successful connection was established and the registry actively responded to the API request, but could not locate the requested image metadata.

  • ✓

    The image tag 'latest' does not exist in the registry

    Why this is correct

    The error "manifest not found" specifically indicates that the container registry was successfully contacted, but it does not contain a schema or manifest matching the requested repository and tag combination. This occurs when the deployment specifies an image tag, such as "latest", that was never pushed to the registry or has been deleted.

  • ✗

    The registry requires authentication and the pod does not have an imagePullSecret

    Why it's wrong here

    When a private registry requires authentication and the pod lacks a valid imagePullSecret, the registry rejects the request with an HTTP 401 Unauthorized or 403 Forbidden status. The resulting Kubernetes event would explicitly state "unauthorized: authentication required" or "pull access denied", rather than indicating that the manifest itself was missing.

  • ✗

    The container runtime is out of disk space

    Why it's wrong here

    Insufficient disk space on the worker node's container storage partition prevents the runtime from extracting or saving the image layers. This condition triggers a "no space left on device" error or disk pressure taints on the node, rather than an upstream registry error indicating that a specific image manifest does not exist.

About these practice questions

Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.