CKAD Practice Question: Application Environment, Configuration and Security
Which THREE of the following are valid fields in a Pod's container spec for resource management? (Choose three.)
⚠ Common exam trap
Watch out — candidates often confuse `resources.requests.storage` with `PersistentVolumeClaim` storage requests, or assume `gpu` is a built-in resource like CPU or memory, when in fact Kubernetes only natively supports CPU and memory as core resources, with extended resources requiring explicit configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
resources.limits.ephemeral-storage
`ephemeral-storage` is a valid resource type in Kubernetes that can be specified under `resources.limits` to control the maximum temporary storage a container can use, preventing pods from exhausting node storage. This is defined in the Kubernetes resource model and is commonly used for scratch space or logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
resources.limits.ephemeral-storage
Why this is correct
resources.limits.ephemeral-storage is a valid field in a container's resources block because ephemeral-storage is one of Kubernetes' three built-in basic resource types, alongside cpu and memory. It caps the amount of local scratch space (e.g., emptyDir volumes, container logs, and image layers) a container may consume, protecting node stability from runaway disk usage. Unlike persistent storage, this quota applies to the pod/container's usage of the node's local ephemeral storage, making it a legitimate resource field under resources.limits.
- ✓
resources.requests.cpu
Why this is correct
resources.requests.cpu is a valid field that specifies the minimum CPU (in cores or millicores) that Kubernetes reserves for a container. This value drives scheduling decisions: the kubelet ensures the node has enough unclaimed CPU capacity to meet the request, and the container is then guaranteed that amount under normal circumstances. It is a core part of the resources specification, and when combined with a corresponding limit, influences the pod's Quality of Service class.
- ✓
resources.limits.memory
Why this is correct
resources.limits.memory is a valid field that sets a hard ceiling on the amount of RAM (in bytes, with suffixes like Gi, Mi, etc.) a container may use. If the container exceeds this limit, the kernel's OOM killer may terminate it, causing a container restart or eviction. This is a standard resource field in Kubernetes, and setting it is critical for preventing a single container from exhausting node memory and destabilizing neighboring pods.
- ✗
resources.requests.gpu
Why it's wrong here
resources.requests.gpu is not a valid field because 'gpu' is not a built-in Kubernetes resource type. Hardware accelerators like GPUs are exposed as extended resources (e.g., nvidia.com/gpu) through device plugins, and they must be requested using that fully qualified extended resource name. Using the generic 'gpu' will cause a validation error or be ignored, since Kubernetes has no intrinsic knowledge of a resource called 'gpu'.
- ✗
resources.requests.storage
Why it's wrong here
resources.requests.storage is not a valid field in a container's resources block because Kubernetes does not allow storage to be requested per-container. Persistent storage is requested via a PersistentVolumeClaim (PVC) object, where the desired size is specified in the PVC's resources.requests.storage field. The container's resources spec only accepts CPU, memory, and ephemeral-storage, so this field is invalid in that context.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.