Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A Pod in a namespace with a ResourceQuota fails to create with the error: 'exceeded quota: compute-quota, requested: pods=1, used: pods=5, limited: pods=5'. What is the issue?

⚠ Common exam trap

CNCF often tests the distinction between count-based quotas (e.g., `count/pods`) and resource-based quotas (e.g., `requests.cpu`), leading candidates to incorrectly assume the error is about resource requests when the message clearly references pod count.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The namespace has reached its maximum number of Pods allowed by the ResourceQuota.

The error message explicitly states 'requested: pods=1, used: pods=5, limited: pods=5'. This means the ResourceQuota named 'compute-quota' has a hard limit of 5 pods in the namespace, and that limit has already been reached. The Pod creation fails because the quota's `count/pods` scope is exhausted, not because of resource requests or permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Pod's service account does not have permission to create Pods.

    Why it's wrong here

    A missing RBAC role binding for the pod's service account causes the API server to reject the create request during authorization, long before admission controllers evaluate ResourceQuota. The error would say `pods is forbidden: User "system:serviceaccount:default:mysa" cannot create resource "pods" in API group ""`, not that a quota has been exceeded. Since ResourceQuota is a validating admission step that runs after authorization, an RBAC failure and a quota failure produce different messages and are diagnosed differently.

  • ✗

    The Pod's resource requests exceed the quota.

    Why it's wrong here

    A ResourceQuota that limits compute resources, such as `requests.cpu` or `requests.memory`, returns an error naming the resource that was exceeded, for example `requested: requests.cpu=1, used: requests.cpu=4, limited: requests.cpu=5`. The error described in the question explicitly mentions `pods=1` and `pods=5`, which indicates a count quota (`count/pods: 5`) rather than a resource-request quota. Furthermore, a pod with zero resource requests can still be rejected by a pod-count quota, so the two failures are independent.

  • ✓

    The namespace has reached its maximum number of Pods allowed by the ResourceQuota.

    Why this is correct

    When a ResourceQuota includes `count/pods: 5`, the Kubernetes API server counts every Pod object in the namespace, regardless of its resource requests or limits. Once five Pods already exist, the admission controller denies another create with an error like `pods "nginx" is forbidden: exceeded quota: my-quota, requested: pods=1, used: pods=5, limited: pods=5`. The namespace is at its ceiling, so no further Pods can be admitted until an existing Pod is deleted or the quota is increased.

  • ✗

    The Pod is trying to mount a Secret that does not exist.

    Why it's wrong here

    A Pod that references a non-existent Secret is still admitted by the API server; the missing Secret is not discovered until the kubelet tries to set up the container's volume mounts or environment variables. This manifests as a `CreateContainerConfigError` pod phase and events saying `Secret "foo" not found`, not as an admission-time rejection. Because the Pod object itself is created successfully, such a failure would not generate an 'exceeded quota' message from the API server.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.