CKAD Application Deployment Practice Question
You run 'kubectl apply -f deployment.yaml' and later 'kubectl replace -f deployment.yaml' on the same file. What is the difference?
⚠ Common exam trap
CKAD often tests the misconception that apply and replace differ only in create-vs-update semantics, when the real distinction is declarative three-way merge versus full object replacement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
apply merges changes, replace replaces the entire resource
'kubectl apply' performs a declarative three-way merge between the last-applied-configuration annotation, the live object, and the new file, so it only changes fields that differ. 'kubectl replace' performs a full replacement of the resource with the contents of the file, overwriting the entire object and failing if the resource does not exist.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
apply merges changes, replace replaces the entire resource
Why this is correct
kubectl apply is declarative: it stores a `last-applied-configuration` annotation, computes a patch against the live object, and performs a three-way merge so changes made by other controllers are preserved, while fields you explicitly removed are deleted. kubectl replace reads the entire YAML/JSON you supply and submits it as the new full object definition, overwriting the live resource outright without merging or reconciling differences with the current state.
- ✗
apply is used for Deployments only, replace for any resource
Why it's wrong here
This is incorrect because both kubectl apply and kubectl replace operate on any Kubernetes resource type, not just Deployments. The API machinery behind apply and replace works generically through the same REST endpoints for Pods, Services, ConfigMaps, custom resources, and everything else. A Deployment is simply one common use case; neither command is restricted to it, so the stated limitation has no basis in kubectl's implementation.
- ✗
apply requires --record flag, replace does not
Why it's wrong here
The `--record` flag is a legacy annotation helper that added a command to the `kubernetes.io/change-cause` annotation; it is now deprecated and unrelated to the core behavior of apply or replace. kubectl apply works fine without `--record` and has never required it to perform a merge, and kubectl replace never needed it either. This option incorrectly ties an optional annotation feature to the fundamental reconciliation strategy of apply.
- ✗
apply creates, replace updates
Why it's wrong here
This is an oversimplification that misstates both commands. kubectl apply creates a resource if it does not exist and updates it if it does, so apply is not merely a create command. kubectl replace is typically used to update an existing resource by sending the entire replacement object, but the meaningful distinction is not create-versus-update; it is declarative merge-based reconciliation (apply) versus imperative full-object replacement (replace).
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.