CKAD Application Design and Build Practice Question
A user runs: kubectl run my-pod --image=nginx --restart=Never --dry-run=client -o yaml. Which apiVersion is used in the generated YAML?
⚠ Common exam trap
The trap here is that candidates often associate `kubectl run` with Deployments (which use `apps/v1`) because that is the default behavior when no `--restart` flag is specified, but the `--restart=Never` flag changes the resource type to a standalone Pod, which uses `v1`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
v1
The `kubectl run` command, when used with `--restart=Never`, creates a standalone Pod. Pods are the most basic Kubernetes resource and belong to the core API group, which uses the `v1` apiVersion (i.e., `apiVersion: v1`). Options like `apps/v1` or `batch/v1` are for higher-level controllers such as Deployments or Jobs, not for a direct Pod creation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
apps/v1
Why it's wrong here
apps/v1 is the API group for controller-managed workload objects such as Deployments, StatefulSets, and DaemonSets, all of which rely on a ReplicaSet or similar controller to maintain desired state. The pod created by `kubectl run ... --restart=Never` is a standalone Pod with no controller managing it, so its manifest must use `apiVersion: v1` and `kind: Pod`. Selecting apps/v1 would imply a Deployment or StatefulSet, which is not what this command generates.
- ✗
batch/v1
Why it's wrong here
batch/v1 is the API group reserved for Job and CronJob objects, which run containers to completion under a retry/backoff policy. Although some kubectl versions can generate Jobs with restart policies like OnFailure or Never, the `--restart=Never` flag specifically tells kubectl to generate a single Pod, not a Job. A Job object would appear as `kind: Job` with `apiVersion: batch/v1`, but here the command output is a Pod, so this group is wrong.
- ✗
networking.k8s.io/v1
Why it's wrong here
networking.k8s.io/v1 is the API group for network configuration resources such as Ingress, IngressClass, and NetworkPolicy, which define routing and pod-network access rules. `kubectl run` is meant to launch an application workload object, not a network rule, so its output never contains `apiVersion: networking.k8s.io/v1`. Associating the generated Pod with this group would be a categorical mistake because Pods are the workload itself, not a declaration about traffic between workloads.
- ✓
v1
Why this is correct
The correct answer is v1, the core Kubernetes API group, which defines foundational resources like Pods, Services, ConfigMaps, and Secrets using the short `apiVersion: v1`. With `--restart=Never`, kubectl's generator emits a standalone Pod manifest with `kind: Pod` and `apiVersion: v1`, served under the `/api/v1` REST endpoint. No other listed group defines a standalone Pod resource, making core v1 the only valid choice.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.