Courseiva

CKA Practice Question: Cluster Architecture, Installation and Configuration

You need to drain a node 'node1' and ensure that pods are evicted gracefully. Which command should you use?

⚠ Common exam trap

Many exam-takers confuse `cordon` (which only prevents new pods) with `drain` (which evicts existing pods), leading them to select option B as a quick fix without understanding that existing workloads remain running.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl drain node1

`kubectl drain node1` safely evicts all pods from the node while respecting PodDisruptionBudgets (PDBs) and graceful termination periods. It cordons the node first (marking it unschedulable) and then evicts pods, ensuring that workloads are rescheduled on other nodes without disruption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl delete node node1

    Why it's wrong here

    Deleting the Node object with `kubectl delete node node1` removes only the control-plane representation of the machine; it never contacts the kubelet and therefore does not terminate or reschedule any of the running Pods. The kubelet continues to run, and if self-registration is enabled, it will simply re-register the Node, leaving node1 in a ready state with workloads intact.

  • ✗

    kubectl cordon node1

    Why it's wrong here

    Cordon only flips the Node's `spec.unschedulable` flag to true, preventing future Pod scheduling onto node1. Because cordon does not touch already running Pods, all existing workloads remain on the node and keep consuming resources, so it is insufficient for a drain where Pods must be moved off before maintenance.

  • ✗

    kubectl taint node node1 key=value:NoSchedule

    Why it's wrong here

    Tainting node1 with a `NoSchedule` effect ensures that new Pods without the matching toleration cannot be scheduled there, but the scheduler never evicts Pods that are already running on a NoSchedule tainted node. Existing Pods continue running unaffected, so the command does nothing to move workloads off the node, unlike drain.

  • ✓

    kubectl drain node1

    Why this is correct

    `kubectl drain node1` first marks the node unschedulable (cordon) and then evicts all non-daemonset, non-mirror Pods via the Eviction API, gracefully terminating them while respecting PodDisruptionBudgets. It is the correct way to prepare a node for maintenance because it actually removes the Pods and reschedules them on other available nodes.

About these practice questions

Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.