CKAD Application Deployment Practice Question
Which TWO statements about kubectl apply vs kubectl create are correct? (Select two)
⚠ Common exam trap
Candidates often confuse the imperative `kubectl create` with the declarative `kubectl apply`, mistakenly believing `create` can update resources or that `apply` is limited to specific resource types.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl apply can update existing resources; kubectl create will error if resource exists
C is correct because `kubectl apply` uses a declarative approach: it creates a resource if it does not exist and updates it if it already exists, merging changes based on the last-applied-configuration annotation. In contrast, `kubectl create` is imperative and will return an error if the resource already exists, as it expects to create a new resource from scratch.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl create can update existing resources if the --force flag is used
Why it's wrong here
kubectl create does not have a --force flag for updating existing resources; --force is used with kubectl delete and kubectl replace to force deletion/recreation, not with create. The create command is designed strictly for new objects and will always fail with an AlreadyExists error if the resource is already present, regardless of any flags.
- ✗
kubectl apply only works with Deployments
Why it's wrong here
kubectl apply is a generic declarative command that works with all Kubernetes resource types, including Deployments, Services, ConfigMaps, Namespaces, and custom resources. It uses a patch-based reconciliation mechanism driven by the last-applied-configuration annotation, so it is not restricted to Deployments. The misconception likely arises from common tutorials that use apply for Deployments, but the feature is resource-agnostic.
- ✓
kubectl apply can update existing resources; kubectl create will error if resource exists
Why this is correct
kubectl apply computes a patch between the desired configuration in your file and the current live object, then merges changes into the existing resource, thus it can update resources. In contrast, kubectl create sends a POST request to the API server and expects to create a brand-new object; if the resource already exists, the API server returns a 409 Conflict error. This fundamental difference makes apply the preferred tool for declarative updates.
- ✗
kubectl create can be used to update resources by providing the full YAML
Why it's wrong here
Providing the full YAML to kubectl create does not enable updating; the command still performs a POST to create a new object, and the API server rejects the request with an AlreadyExists error if the resource is already present. For updates, you need kubectl apply for a declarative merge, kubectl edit for an interactive edit, or kubectl replace for an imperative replacement. The mere presence of complete YAML does not change create's creation-only semantics.
- ✓
kubectl apply maintains a last-applied-configuration annotation; kubectl create does not
Why this is correct
kubectl apply stores the exact configuration you provide in the kubectl.kubernetes.io/last-applied-configuration annotation, which is then used on subsequent applies to perform a three-way merge among the original, current, and desired states. kubectl create does not add this annotation by default; it simply posts the object to the API server and moves on. This annotation is what enables apply to know which fields were deleted from the configuration and remove them from the live object, giving it powerful declarative update capabilities.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.