Courseiva

CKA Practice Question: Cluster Architecture, Installation and Configuration

You need to back up the etcd database for a kubeadm-created cluster. Which directory contains the etcd data?

⚠ Common exam trap

Test-takers frequently confuse the etcd data directory with the certificate directory (`/etc/kubernetes/pki/etcd`) because both are etcd-related and located under `/etc/kubernetes`, but only the data directory holds the actual database files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/var/lib/etcd

For a kubeadm-created cluster, etcd runs as a static Pod, and its data directory is mounted from the host path `/var/lib/etcd`. This is the default data directory used by etcd when started via kubeadm, and it stores all cluster state and configuration data. The CKA exam expects you to know this path for backup and restore operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    /etc/kubernetes/pki/etcd

    Why it's wrong here

    /etc/kubernetes/pki/etcd contains the etcd CA and member/client certificates and private keys (ca.crt, server.crt, server.key, etc.) used to secure communication between the API server and etcd. While these PKI files are critical for authenticating the etcd member and must be backed up to restore a cluster with the same TLS identities, they represent the identity of the etcd server, not the data it stores. Backing up this directory alone captures no Kubernetes objects, namespaces, secrets, or any other key-value data, so it is not a valid location for an etcd data backup.

  • ✓

    /var/lib/etcd

    Why this is correct

    /var/lib/etcd is the default etcd data directory for kubeadm-created clusters, configured as the hostPath mount for the etcd static pod and defined by the `--data-dir` flag. This directory contains the etcd member's key-value store, WAL (write-ahead log), and snapshots, representing the authoritative persistence layer for all cluster state. To back up etcd data, you would typically run `etcdctl snapshot save` while the cluster is running, or stop etcd and copy this directory for a cold backup; in either case, this path is the correct source of the data.

  • ✗

    /var/lib/kubelet

    Why it's wrong here

    /var/lib/kubelet is the kubelet's local working directory, storing node-specific runtime data such as pod sandbox contents, volume mounts (including emptyDir and hostPath volumes), and container logs. This directory is managed by the kubelet and reflects the state of pods running on that particular node, not the cluster-wide desired state maintained in etcd. The kubelet data is ephemeral and node-local, so copying it would not capture the authoritative API object state (e.g., Deployments, Services, ConfigMaps) that lives in etcd, making it an incorrect backup target for cluster state.

  • ✗

    /etc/etcd

    Why it's wrong here

    /etc/etcd is a conventional location on some Linux distributions for etcd configuration files, such as etcd.conf.yml, and may hold certificates or CA files for TLS. However, in a kubeadm cluster, etcd's configuration is not centralized here; instead, the static pod manifest for etcd is located at /etc/kubernetes/manifests/etcd.yaml, and the actual data directory is overridden to /var/lib/etcd. The /etc/etcd directory contains only operational configuration that can be regenerated with `kubeadm init` or by restoring manifests, and it does not contain any of the key-value data persisted by etcd, so backing it up would fail to preserve cluster state.

About these practice questions

Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.