Courseiva
Troubleshooting →easyMultiple Choice

CKA Troubleshooting Practice Question

You run 'kubectl get events --sort-by='.lastTimestamp'' and see repeated events: 'Failed to pull image "myimage:v2": rpc error: code = Unknown desc = Error response from daemon: manifest for myimage:v2 not found'. What is the issue?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The image tag 'myimage:v2' does not exist in the registry.

The error 'manifest not found' means the image tag does not exist in the registry. The pod is in ImagePullBackOff because the image is missing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The pod has insufficient privileges to pull the image.

    Why it's wrong here

    If the pod lacked privileges to pull the image, you'd see registry authentication errors like 'unauthorized: authentication required' or 'denied: requested access to the resource is denied' (HTTP 401/403), not a manifest-not-found error. Furthermore, image pulls are performed by the kubelet using node-level credentials or imagePullSecrets; the pod's own RBAC service account does not directly authorize registry access. Therefore, an 'insufficient privileges' error would indicate a credential problem, not a missing tag.

  • ✗

    The image registry is down.

    Why it's wrong here

    If the registry were down, the kubelet would fail to establish a TCP connection or negotiate TLS, producing errors such as 'dial tcp: connection refused', 'i/o timeout', or 'x509: certificate signed by unknown authority'. A 'manifest unknown' message is an actual HTTP 404 response from the registry, which proves the registry is online and reachable. Thus, a down registry cannot produce a manifest-not-found error because no response would be received at all.

  • ✗

    The container runtime is not running.

    Why it's wrong here

    A non-running container runtime (e.g., containerd or CRI-O) would prevent the kubelet from communicating over the CRI socket, yielding errors like 'failed to get image status' or 'cannot connect to the runtime endpoint'. These errors affect all container operations, not just image pulls for one pod. The specific 'manifest unknown' error is generated by the registry itself and returned through the runtime, meaning the runtime successfully queried the registry; therefore the runtime must be functioning.

  • ✓

    The image tag 'myimage:v2' does not exist in the registry.

    Why this is correct

    The error message for a missing tag in a registry is typically 'manifest unknown' or 'not found' (HTTP 404). The question states that the error clearly indicates the manifest is not found for the tag 'myimage:v2', which means that specific tag does not exist in the registry. This is a definitive registry-side response: the registry is reachable, the repository may exist, but the requested tag has no associated manifest.

About these practice questions

This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.