CKA Practice Question: Cluster Architecture, Installation and Configuration
You need to back up the etcd database for a kubeadm-created cluster. Which directory contains the etcd data?
⚠ Common exam trap
Test-takers frequently confuse the etcd data directory with the certificate directory (`/etc/kubernetes/pki/etcd`) because both are etcd-related and located under `/etc/kubernetes`, but only the data directory holds the actual database files.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/var/lib/etcd
For a kubeadm-created cluster, etcd runs as a static Pod, and its data directory is mounted from the host path `/var/lib/etcd`. This is the default data directory used by etcd when started via kubeadm, and it stores all cluster state and configuration data. The CKA exam expects you to know this path for backup and restore operations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
/etc/kubernetes/pki/etcd
Why it's wrong here
/etc/kubernetes/pki/etcd contains the etcd CA and member/client certificates and private keys (ca.crt, server.crt, server.key, etc.) used to secure communication between the API server and etcd. While these PKI files are critical for authenticating the etcd member and must be backed up to restore a cluster with the same TLS identities, they represent the identity of the etcd server, not the data it stores. Backing up this directory alone captures no Kubernetes objects, namespaces, secrets, or any other key-value data, so it is not a valid location for an etcd data backup.
- ✓
/var/lib/etcd
Why this is correct
/var/lib/etcd is the default etcd data directory for kubeadm-created clusters, configured as the hostPath mount for the etcd static pod and defined by the `--data-dir` flag. This directory contains the etcd member's key-value store, WAL (write-ahead log), and snapshots, representing the authoritative persistence layer for all cluster state. To back up etcd data, you would typically run `etcdctl snapshot save` while the cluster is running, or stop etcd and copy this directory for a cold backup; in either case, this path is the correct source of the data.
- ✗
/var/lib/kubelet
Why it's wrong here
/var/lib/kubelet is the kubelet's local working directory, storing node-specific runtime data such as pod sandbox contents, volume mounts (including emptyDir and hostPath volumes), and container logs. This directory is managed by the kubelet and reflects the state of pods running on that particular node, not the cluster-wide desired state maintained in etcd. The kubelet data is ephemeral and node-local, so copying it would not capture the authoritative API object state (e.g., Deployments, Services, ConfigMaps) that lives in etcd, making it an incorrect backup target for cluster state.
- ✗
/etc/etcd
Why it's wrong here
/etc/etcd is a conventional location on some Linux distributions for etcd configuration files, such as etcd.conf.yml, and may hold certificates or CA files for TLS. However, in a kubeadm cluster, etcd's configuration is not centralized here; instead, the static pod manifest for etcd is located at /etc/kubernetes/manifests/etcd.yaml, and the actual data directory is overridden to /var/lib/etcd. The /etc/etcd directory contains only operational configuration that can be regenerated with `kubeadm init` or by restoring manifests, and it does not contain any of the key-value data persisted by etcd, so backing it up would fail to preserve cluster state.
Go deeper
Related to this question
Learn chapter
etcd Backup and Restore
Key term
Taints and Tolerations
Taints and tolerations are Kubernetes features that control which pods can be scheduled onto which nodes by marking nodes with a taint and allowing pods to declare a toleration to the taint.
Key term
Kubernetes Node Roles
Kubernetes Node Roles are labels assigned to machines in a cluster that define whether a node runs application containers (worker) or manages the cluster (control plane).
About these practice questions
Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.