Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

You apply a ResourceQuota to a namespace that limits memory requests to 2Gi. You then try to create a pod that requests 3Gi memory. What happens?

⚠ Common exam trap

Watch out — candidates often confuse ResourceQuota (which enforces at admission time and rejects the pod) with LimitRange (which sets default requests/limits but does not cap existing requests), or mistakenly think Kubernetes silently adjusts resource requests to fit within quotas.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The pod creation fails with an error message indicating the quota would be exceeded.

When a ResourceQuota is applied to a namespace with a memory request limit of 2Gi, any pod creation that would cause the total memory requests in the namespace to exceed that quota is rejected by the Kubernetes API server. The pod creation fails immediately with an error message indicating the quota would be exceeded, because the admission controller validates the request against the quota before allowing the pod to be scheduled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The pod is created with a warning, but the request is ignored.

    Why it's wrong here

    The Kubernetes API server enforces ResourceQuota during admission control, which happens before a pod is accepted. A request that would exceed the remaining memory quota is not allowed through with a warning; the server responds with an HTTP error such as 403 Forbidden. Warnings in Kubernetes are advisory messages that do not bypass admission decisions, so the pod is never created. Therefore this option is incorrect because creation is blocked, not silently allowed.

  • ✗

    The pod is created, but the memory request is capped at 2Gi.

    Why it's wrong here

    ResourceQuota is a namespace-scoped admission control object that aggregates resource requests and limits; it does not mutate or rewrite a pod specification. A LimitRange is the mechanism that can apply default requests or caps to individual pods, but a quota alone never modifies fields. If a pod's declared memory request exceeds the quota's remaining capacity, the creation request is rejected by the API server rather than being admitted with a lower value. Thus this option is wrong because quotas deny admission instead of silently capping values.

  • ✓

    The pod creation fails with an error message indicating the quota would be exceeded.

    Why this is correct

    This is the correct behavior because ResourceQuota validation runs as an admission controller in the API server. When a pod's memory request would push the namespace's aggregated usage over the quota limit, the server rejects the Create request with a clear error message, typically starting with 'quota exceeded' and detailing requested, used, and limited amounts. The rejection occurs synchronously before the pod is persisted, so no pod object is ever created. This is exactly how admission control is designed to protect finite namespace-level resources.

  • ✗

    The pod is created, but it will be OOMKilled if it exceeds 2Gi.

    Why it's wrong here

    ResourceQuota operates only at admission time and has no direct role in the kernel's OOM killer behavior. An OOMKilled status results from a container exceeding its memory limit as enforced by cgroups, which is configured via the container's limits, not by a namespace quota. Since the pod creation would be rejected before it can run, there is no process to be OOMKilled. This option is wrong because it ignores the admission-time failure and conflates quota enforcement with runtime memory limits.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.