Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A pod is stuck in Pending state. You run 'kubectl describe pod my-pod' and see the event: '0/4 nodes are available: 1 Insufficient cpu, 3 Insufficient memory'. What is the most likely cause?

⚠ Common exam trap

It's easy for candidates to confuse resource requests with resource limits, thinking that low limits cause scheduling failures, but Kubernetes only uses requests for scheduling decisions, not limits.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The pod's resource requests exceed the available node resources

The event '0/4 nodes are available: 1 Insufficient cpu, 3 Insufficient memory' indicates that the Kubernetes scheduler could not find any node that satisfies the pod's resource requests. The pod's resource requests (spec.containers[].resources.requests) define the minimum CPU and memory the pod requires to run. If the sum of requests across all pods on a node exceeds the node's allocatable resources, the scheduler marks the node as unschedulable for that pod, leaving it in Pending state.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The pod's resource requests exceed the available node resources

    Why this is correct

    The Kubernetes scheduler selects a node based on the resource requests (CPU and memory) declared in the pod spec. If no node has enough allocatable resources to satisfy those requests after accounting for the requests of existing pods, the scheduler cannot place the pod, leaving it in Pending state. This is the most common cause of Pending, and `kubectl describe` typically shows FailedScheduling events with reasons like 'Insufficient cpu' or 'Insufficient memory'.

  • ✗

    The pod uses too many secrets

    Why it's wrong here

    Secrets are mounted as files or environment variables by the kubelet after a pod has been assigned to a node, so they are never considered during the scheduling process. The kube-scheduler only evaluates compute resources, node labels, and affinity constraints, not the pod's secret references. Even if a referenced secret is missing or overly large, the pod would still be scheduled; it would instead fail later with a CreateContainerConfigError or a mount failure, not remain Pending.

  • ✗

    The pod's resource limits are too low

    Why it's wrong here

    Resource limits are enforcement constraints applied by the kubelet after scheduling, not at placement time; they control how much CPU or memory a container can consume, not whether a node has capacity for it. The scheduler only checks requests, which are the guaranteed amounts, and limits are usually higher than requests. Thus, low limits might cause a running container to be throttled or killed with an OOMKilled status, but they would never prevent the scheduler from placing the pod and would not keep it in Pending.

  • ✗

    The pod's container is failing health checks

    Why it's wrong here

    Health checks (liveness and readiness probes) are executed by the kubelet only after the container has been started on a node, which by definition means the pod is already scheduled and no longer Pending. A failing liveness probe triggers restarts and eventually CrashLoopBackOff, while a failing readiness probe removes the pod from Service endpoints without altering its phase. Since Pending indicates the scheduler has not yet chosen a node, there is no container running to probe, so health check failures cannot be the cause.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.