CKAD Practice Question: Application Environment, Configuration and Security
You deploy a pod with resource requests: cpu: 500m, memory: 256Mi and limits: cpu: 1, memory: 512Mi. The container tries to allocate 600Mi of memory. What happens?
⚠ Common exam trap
CNCF often tests the misconception that memory, like CPU, can be throttled when limits are exceeded, but memory is a non-compressible resource and exceeding its limit always results in an OOM kill, not throttling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The container is OOMKilled because it exceeds the memory limit
The container's memory allocation of 600Mi exceeds its configured memory limit of 512Mi. Kubernetes enforces memory limits using the cgroup memory controller; when a container attempts to allocate more memory than its limit, the kernel's Out-Of-Memory (OOM) killer terminates the container process. This results in the container being OOMKilled, as recorded in the pod status.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The container is OOMKilled because it exceeds the memory limit
Why this is correct
The container is OOMKilled because it exceeds the memory limit. Memory limits are enforced via a cgroup; when the container's memory usage surpasses that limit, the kernel's OOM killer terminates the offending process. This results in the pod's container being marked as OOMKilled with exit code 137, and Kubernetes restarts it according to the restart policy.
- ✗
The container runs normally, but memory usage is throttled
Why it's wrong here
The container runs normally, but memory usage is throttled. This is incorrect because memory cannot be throttled like CPU. CPU limits are implemented via CFS bandwidth control, which limits the amount of CPU time per period, causing throttling. Memory has no analogous throttling mechanism; exceeding a memory limit directly triggers the OOM killer rather than slowing the container down.
- ✗
The container runs normally because requests are the only constraints
Why it's wrong here
The container runs normally because requests are the only constraints. Requests are used for scheduling and weighing node capacity, but limits are separate enforcement parameters. Since a memory limit is configured (as stated in the scenario), exceeding it triggers an OOM kill, not normal operation. Requests alone do not constrain runtime memory usage; limits do.
- ✗
The container is evicted from the node
Why it's wrong here
The container is evicted from the node. Eviction is a node-level behavior driven by node pressure (such as memory pressure or disk pressure), based on pod requests and node allocatable resources. A container exceeding its own memory limit causes a cgroup-level OOM kill of that container, not an eviction of the entire pod from the node. Evictions are typically initiated by the kubelet, not by the kernel OOM killer.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.