CKAD Practice Question: Application Environment, Configuration and Security
You create a ResourceQuota in a namespace that sets requests.cpu: '1' and limits.cpu: '2'. A pod spec has no resource limits or requests. What happens when you try to create this pod?
⚠ Common exam trap
A common mix-up: candidates assume a LimitRange will automatically apply default resource values, but without a LimitRange, the pod creation is denied outright due to the missing fields required by the ResourceQuota.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The pod creation is denied because the spec does not specify resource limits or requests
When a ResourceQuota is defined with requests.cpu and limits.cpu, Kubernetes requires that every pod in that namespace have explicit resource requests and limits that match the quota constraints. If a pod spec omits these fields, the API server denies the pod creation because it cannot determine whether the pod complies with the quota. This is enforced at admission time, not at runtime.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The pod is created without limits, but the quota is enforced at runtime
Why it's wrong here
ResourceQuota is enforced by the Kubernetes admission controller at the moment a pod is created or updated, not at runtime. If the pod spec lacks the required resource requests or limits, the API server rejects the admission request before the pod is ever scheduled or run, so a quota cannot be 'enforced at runtime'.
- ✓
The pod creation is denied because the spec does not specify resource limits or requests
Why this is correct
When a ResourceQuota is active in a namespace, it imposes an admission-time validation that every pod in that namespace must specify resource requests (and limits if the quota includes limits). Because the pod spec in this scenario omits both resource limits and requests, the admission controller denies creation—there is nothing to count against the quota, so the request fails.
- ✗
The pod is created and the quota is ignored
Why it's wrong here
A ResourceQuota cannot be ignored once it is configured; it is part of the cluster's admission control chain that evaluates every pod creation or update request in the namespace. The API server will not persist a pod that violates the quota constraints, and it will return an error to the user instead of silently accepting the pod.
- ✗
The pod is created with default limits from the LimitRange
Why it's wrong here
Default resource limits are only applied by a LimitRange object, not by a ResourceQuota. Since the question makes no mention of a LimitRange, the API server has no mechanism to inject default requests or limits; without an explicit LimitRange, a pod missing resource specifications is rejected by the quota rather than being defaulted.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.