CKA Practice Question: Cluster Architecture, Installation and Configuration
You have an etcd cluster with three members. You need to take a snapshot for disaster recovery. Which command correctly creates a snapshot?
⚠ Common exam trap
The trap here is that candidates often forget to include TLS flags or the `--endpoints` flag, assuming a local default connection works, or they confuse `snapshot save` with `snapshot restore` or the deprecated v2 API backup command.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ETCDCTL_API=3 etcdctl snapshot save /backup/snapshot.db --endpoints=https://127.0.0.1:2379 --cacert=/etc/kubernetes/pki/etcd/ca.crt --cert=/etc/kubernetes/pki/etcd/server.crt --key=/etc/kubernetes/pki/etcd/server.key
It uses the etcdctl v3 API with the `snapshot save` command, which is the proper method for creating a consistent point-in-time backup of an etcd cluster. The command includes mandatory TLS authentication flags (`--cacert`, `--cert`, `--key`) and the `--endpoints` flag to target a specific etcd member, ensuring a secure and successful snapshot operation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
etcdctl snapshot restore /backup/snapshot.db
Why it's wrong here
This command is used to restore an existing etcd snapshot to a data directory, rather than taking a new backup. Additionally, executing it without specifying the API version or providing the necessary TLS certificates and endpoints will fail to interact with a secure Kubernetes etcd cluster.
- ✗
ETCDCTL_API=2 etcdctl backup --data-dir /var/lib/etcd
Why it's wrong here
This command incorrectly utilizes the deprecated v2 API and the legacy backup subcommand, which is incompatible with the v3 data store used by modern Kubernetes clusters. To capture a consistent state of a running Kubernetes etcd database, you must use the v3 API's snapshot save command instead of copying raw data files.
- ✓
ETCDCTL_API=3 etcdctl snapshot save /backup/snapshot.db --endpoints=https://127.0.0.1:2379 --cacert=/etc/kubernetes/pki/etcd/ca.crt --cert=/etc/kubernetes/pki/etcd/server.crt --key=/etc/kubernetes/pki/etcd/server.key
Why this is correct
This is the correct command because it explicitly sets the environment variable to use the v3 API and specifies the snapshot save subcommand. It also correctly provides the secure loopback endpoint along with the mandatory CA certificate, client certificate, and private key required to authenticate against a TLS-secured etcd cluster.
- ✗
etcdctl snapshot save /backup/snapshot.db
Why it's wrong here
Although this command uses the correct snapshot save subcommand, it will fail in a standard, secure Kubernetes environment because it lacks the necessary TLS authentication parameters. Without specifying the endpoints, CA certificate, client certificate, and private key, the etcdctl client cannot establish a trusted connection to the encrypted etcd member.
Go deeper
Related to this question
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.