Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

Which TWO are correct about LimitRange?

⚠ Common exam trap

Many candidates confuse LimitRange (per-container constraints and defaults) with ResourceQuota (aggregate namespace limits), leading candidates to incorrectly select option D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

LimitRange can set default resource requests for containers that don't specify them

A LimitRange can define default resource requests and limits for containers in a namespace. When a container is created without specifying resource requests or limits, the LimitRange admission controller automatically applies the default values defined in the LimitRange object. This ensures that containers have baseline resource guarantees even if the pod spec omits them.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    LimitRange can set default resource requests for containers that don't specify them

    Why this is correct

    LimitRange's spec.default section defines default resource requests and limits for containers that do not explicitly declare them. When a pod is created in a namespace with a LimitRange, any container lacking a request or limit for a resource specified in default is automatically assigned that value. This defaulting mechanism applies at admission time, so it does not retroactively modify existing pods, and it works alongside the min/max constraints to keep pods within acceptable boundaries.

  • ✗

    LimitRange can be applied only to pods in the default namespace

    Why it's wrong here

    A LimitRange is a namespaced resource, meaning you can create it in any namespace, not just the default namespace. Once created, it applies only to pods within that specific namespace; it has no effect on pods in other namespaces. The statement is wrong because it incorrectly restricts LimitRange to the default namespace, whereas the actual constraint is that a LimitRange is always tied to the namespace in which it is defined.

  • ✗

    LimitRange is a cluster-scoped resource

    Why it's wrong here

    LimitRange is not a cluster-scoped resource; it is namespaced, just like ConfigMap, Secret, and Service. Cluster-scoped resources include Node, PersistentVolume, and Namespace, which are visible and managed at the cluster level, whereas a LimitRange is contained within a single namespace and affects only that namespace's pods. The confusion may arise because 'cluster' sometimes loosely refers to all namespaces, but Kubernetes API resources have an explicit scope that categorizes LimitRange as namespaced.

  • ✗

    LimitRange can enforce quotas on total resource usage across all pods

    Why it's wrong here

    ResourceQuota, not LimitRange, is the mechanism for enforcing aggregate resource consumption across all pods and other objects in a namespace. A LimitRange constrains individual containers or pods—for example, setting a maximum memory limit per container—but it does not sum total usage across the namespace. If you need to cap total CPU or memory requests, you must create a ResourceQuota, which counts the sum of requests/limits from all objects and rejects creations that would exceed the quota.

  • ✓

    LimitRange can set maximum resource limits for containers

    Why this is correct

    Through its spec.max field, a LimitRange sets the maximum allowable resource limit for a container or pod in the namespace. If a pod's explicit resource limit exceeds the value specified in spec.max, the pod is rejected by the admission controller. This is an upper bound; it pairs with spec.min (lower bound) and spec.default to provide a complete policy for resource requests and limits.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.