Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

You deploy a pod with resource requests: cpu: 500m, memory: 256Mi and limits: cpu: 1, memory: 512Mi. The container tries to allocate 600Mi of memory. What happens?

⚠ Common exam trap

CNCF often tests the misconception that memory, like CPU, can be throttled when limits are exceeded, but memory is a non-compressible resource and exceeding its limit always results in an OOM kill, not throttling.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The container is OOMKilled because it exceeds the memory limit

The container's memory allocation of 600Mi exceeds its configured memory limit of 512Mi. Kubernetes enforces memory limits using the cgroup memory controller; when a container attempts to allocate more memory than its limit, the kernel's Out-Of-Memory (OOM) killer terminates the container process. This results in the container being OOMKilled, as recorded in the pod status.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The container is OOMKilled because it exceeds the memory limit

    Why this is correct

    The container is OOMKilled because it exceeds the memory limit. Memory limits are enforced via a cgroup; when the container's memory usage surpasses that limit, the kernel's OOM killer terminates the offending process. This results in the pod's container being marked as OOMKilled with exit code 137, and Kubernetes restarts it according to the restart policy.

  • ✗

    The container runs normally, but memory usage is throttled

    Why it's wrong here

    The container runs normally, but memory usage is throttled. This is incorrect because memory cannot be throttled like CPU. CPU limits are implemented via CFS bandwidth control, which limits the amount of CPU time per period, causing throttling. Memory has no analogous throttling mechanism; exceeding a memory limit directly triggers the OOM killer rather than slowing the container down.

  • ✗

    The container runs normally because requests are the only constraints

    Why it's wrong here

    The container runs normally because requests are the only constraints. Requests are used for scheduling and weighing node capacity, but limits are separate enforcement parameters. Since a memory limit is configured (as stated in the scenario), exceeding it triggers an OOM kill, not normal operation. Requests alone do not constrain runtime memory usage; limits do.

  • ✗

    The container is evicted from the node

    Why it's wrong here

    The container is evicted from the node. Eviction is a node-level behavior driven by node pressure (such as memory pressure or disk pressure), based on pod requests and node allocatable resources. A container exceeding its own memory limit causes a cgroup-level OOM kill of that container, not an eviction of the entire pod from the node. Evictions are typically initiated by the kubelet, not by the kernel OOM killer.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.