CKAD Practice Question: Application Environment, Configuration and Security
A cluster administrator wants to enforce that no pod in namespace 'prod' uses more than 4Gi of memory. Which Kubernetes resource should be created?
⚠ Common exam trap
Test-takers frequently confuse ResourceQuota (namespace-level aggregate limits) with LimitRange (per-pod/per-container limits), leading candidates to select D when the question explicitly asks for per-pod enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
LimitRange
A LimitRange resource in the 'prod' namespace can set a default memory limit and a maximum memory limit per container or pod, enforcing that no pod exceeds 4Gi of memory. This is the appropriate Kubernetes primitive for per-pod resource constraints within a namespace, as it applies to all pods that do not specify their own limits.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PodDisruptionBudget
Why it's wrong here
A PodDisruptionBudget (PDB) specifies the minimum number or percentage of pods that must remain available during voluntary disruptions like node drains or cluster upgrades. It does not impose any CPU or memory constraints per pod, so it cannot enforce a maximum memory limit. While a PDB helps maintain availability, it never evaluates resource requests or limits during pod admission.
- ✗
NetworkPolicy
Why it's wrong here
A NetworkPolicy controls which pods or namespaces can communicate with each other through ingress and egress rules based on labels, IP blocks, or ports. It operates at the network layer and has no mechanism to define memory or CPU limits for containers. Therefore, it is completely unrelated to enforcing a per-pod maximum memory limit.
- ✓
LimitRange
Why this is correct
A LimitRange is a namespace-scoped resource that defines minimum, maximum, and default values for CPU and memory requests and limits per container or pod. Setting a max limit in a LimitRange ensures that any pod that declares a memory limit exceeding that maximum is rejected during admission control. It also can set default requests/limits for pods that do not specify them, giving the administrator direct control over per-pod resource bounds.
- ✗
ResourceQuota
Why it's wrong here
A ResourceQuota constrains the aggregate amount of CPU, memory, or other objects consumed across all pods and workloads in a namespace, such as a total memory limit of 8Gi. It does not enforce a per-pod cap; a single pod could theoretically consume the entire quota while others remain unschedulable. Thus it manages cumulative consumption, not individual pod limits.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.