Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A namespace 'team-a' has a ResourceQuota that sets 'requests.cpu: 4' and 'limits.cpu: 8'. A developer tries to create a pod with 'resources.requests.cpu: 2' and 'resources.limits.cpu: 10'. What happens?

⚠ Common exam trap

A common mix-up: candidates assume only the request is checked against the quota, but Kubernetes enforces both requests and limits independently, and a pod with a limit exceeding the quota's limit will be rejected even if the request is within bounds.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The pod is rejected because the limit (10) exceeds the quota's allowed limit

The pod is rejected because the ResourceQuota in namespace 'team-a' sets a hard limit of 8 CPUs for limits.cpu across all pods. The developer's pod specifies a limit of 10 CPUs, which exceeds this quota. Kubernetes enforces ResourceQuota at admission time, so any resource request or limit that violates the quota's constraints will cause the pod creation to be denied.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The pod is rejected because the limit (10) exceeds the quota's allowed limit

    Why this is correct

    When a ResourceQuota is active in a namespace, the API server enforces it during admission control by summing the resource limits of all existing objects and comparing them to the quota. A new Pod with a limit of 10 exceeds the namespace's allowed limit total of 8, so the API server rejects the creation with a 403 Forbidden response. The Pod is never persisted to etcd and never reaches the scheduler.

  • ✗

    The pod is created because the request (2) is within the quota

    Why it's wrong here

    A ResourceQuota does not check requests and limits in isolation; it maintains separate aggregates for resource.requests and resource.limits. Even if the Pod's request of 2 is within the request quota, the limit of 10 violates the limits quota. Because the API server evaluates both dimensions and rejects the admission request if any quota is exceeded, the Pod is not created.

  • ✗

    The pod is created but its limit is automatically reduced to 8

    Why it's wrong here

    Kubernetes has no mechanism to automatically reduce or clamp a Pod's resource limits to fit a quota. The admission controller only validates the submitted object and either accepts or rejects it; it never mutates user-specified values. If a limit exceeds the available quota, the creation fails outright rather than being silently adjusted to 8.

  • ✗

    The pod is created, but it will be evicted immediately

    Why it's wrong here

    Eviction is a kubelet runtime action triggered by actual resource pressure on a node and can only affect Pods that have been successfully admitted and scheduled. Here, the API server rejects the Pod during admission control, so no Pod object exists, no containers start, and no node is involved. Therefore, there is nothing to evict; the rejection occurs before any runtime action can take place.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.