CKA Practice Question: Cluster Architecture, Installation and Configuration
You need to drain a node 'node1' and ensure that pods are evicted gracefully. Which command should you use?
⚠ Common exam trap
Many exam-takers confuse `cordon` (which only prevents new pods) with `drain` (which evicts existing pods), leading them to select option B as a quick fix without understanding that existing workloads remain running.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl drain node1
`kubectl drain node1` safely evicts all pods from the node while respecting PodDisruptionBudgets (PDBs) and graceful termination periods. It cordons the node first (marking it unschedulable) and then evicts pods, ensuring that workloads are rescheduled on other nodes without disruption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl delete node node1
Why it's wrong here
Deleting the Node object with `kubectl delete node node1` removes only the control-plane representation of the machine; it never contacts the kubelet and therefore does not terminate or reschedule any of the running Pods. The kubelet continues to run, and if self-registration is enabled, it will simply re-register the Node, leaving node1 in a ready state with workloads intact.
- ✗
kubectl cordon node1
Why it's wrong here
Cordon only flips the Node's `spec.unschedulable` flag to true, preventing future Pod scheduling onto node1. Because cordon does not touch already running Pods, all existing workloads remain on the node and keep consuming resources, so it is insufficient for a drain where Pods must be moved off before maintenance.
- ✗
kubectl taint node node1 key=value:NoSchedule
Why it's wrong here
Tainting node1 with a `NoSchedule` effect ensures that new Pods without the matching toleration cannot be scheduled there, but the scheduler never evicts Pods that are already running on a NoSchedule tainted node. Existing Pods continue running unaffected, so the command does nothing to move workloads off the node, unlike drain.
- ✓
kubectl drain node1
Why this is correct
`kubectl drain node1` first marks the node unschedulable (cordon) and then evicts all non-daemonset, non-mirror Pods via the Eviction API, gracefully terminating them while respecting PodDisruptionBudgets. It is the correct way to prepare a node for maintenance because it actually removes the Pods and reschedules them on other available nodes.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.