Courseiva

CKA Practice Question: Cluster Architecture, Installation and Configuration

You have an etcd cluster with three members. You need to take a snapshot for disaster recovery. Which command correctly creates a snapshot?

⚠ Common exam trap

The trap here is that candidates often forget to include TLS flags or the `--endpoints` flag, assuming a local default connection works, or they confuse `snapshot save` with `snapshot restore` or the deprecated v2 API backup command.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ETCDCTL_API=3 etcdctl snapshot save /backup/snapshot.db --endpoints=https://127.0.0.1:2379 --cacert=/etc/kubernetes/pki/etcd/ca.crt --cert=/etc/kubernetes/pki/etcd/server.crt --key=/etc/kubernetes/pki/etcd/server.key

It uses the etcdctl v3 API with the `snapshot save` command, which is the proper method for creating a consistent point-in-time backup of an etcd cluster. The command includes mandatory TLS authentication flags (`--cacert`, `--cert`, `--key`) and the `--endpoints` flag to target a specific etcd member, ensuring a secure and successful snapshot operation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    etcdctl snapshot restore /backup/snapshot.db

    Why it's wrong here

    This command is used to restore an existing etcd snapshot to a data directory, rather than taking a new backup. Additionally, executing it without specifying the API version or providing the necessary TLS certificates and endpoints will fail to interact with a secure Kubernetes etcd cluster.

  • ✗

    ETCDCTL_API=2 etcdctl backup --data-dir /var/lib/etcd

    Why it's wrong here

    This command incorrectly utilizes the deprecated v2 API and the legacy backup subcommand, which is incompatible with the v3 data store used by modern Kubernetes clusters. To capture a consistent state of a running Kubernetes etcd database, you must use the v3 API's snapshot save command instead of copying raw data files.

  • ✓

    ETCDCTL_API=3 etcdctl snapshot save /backup/snapshot.db --endpoints=https://127.0.0.1:2379 --cacert=/etc/kubernetes/pki/etcd/ca.crt --cert=/etc/kubernetes/pki/etcd/server.crt --key=/etc/kubernetes/pki/etcd/server.key

    Why this is correct

    This is the correct command because it explicitly sets the environment variable to use the v3 API and specifies the snapshot save subcommand. It also correctly provides the secure loopback endpoint along with the mandatory CA certificate, client certificate, and private key required to authenticate against a TLS-secured etcd cluster.

  • ✗

    etcdctl snapshot save /backup/snapshot.db

    Why it's wrong here

    Although this command uses the correct snapshot save subcommand, it will fail in a standard, secure Kubernetes environment because it lacks the necessary TLS authentication parameters. Without specifying the endpoints, CA certificate, client certificate, and private key, the etcdctl client cannot establish a trusted connection to the encrypted etcd member.

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.