CKAD Application Design and Build Practice Question
You run 'kubectl run nginx --image=nginx --restart=Never --dry-run=client -o yaml'. What is the output?
⚠ Common exam trap
Candidates often assume `kubectl run` always creates a Deployment, forgetting that the `--restart` flag changes the resource type, and they may also mistakenly think Pods use a beta API version.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Pod manifest with apiVersion: v1
The command `kubectl run nginx --image=nginx --restart=Never --dry-run=client -o yaml` creates a Pod manifest because `--restart=Never` explicitly sets the restart policy to Never, which is a Pod-level field. The `kubectl run` command without `--restart=Never` defaults to creating a Deployment, but with `--restart=Never`, it generates a standalone Pod. The output uses `apiVersion: v1`, which is the correct and stable API version for Pods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A Pod manifest with apiVersion: v1beta1
Why it's wrong here
A Pod manifest with `apiVersion: v1beta1` is invalid because Pods are a core resource served under the stable `v1` API, not a beta API. The `v1beta1` prefix indicates a pre-release, deprecated API version that has been disabled and eventually removed in modern Kubernetes clusters. `kubectl run --restart=Never` always emits a core/v1 Pod manifest, so no beta version would ever appear.
- ✓
A Pod manifest with apiVersion: v1
Why this is correct
Running `kubectl run nginx --image=nginx --restart=Never` generates a standalone Pod manifest with `apiVersion: v1` and `kind: Pod`, because `--restart=Never` explicitly disables controller-managed restart behavior. The core `v1` API is the correct, stable group/version for Pods. This single-container manifest simply declares the nginx image and a `restartPolicy: Never` in the Pod spec.
- ✗
A Job manifest with apiVersion: batch/v1
Why it's wrong here
A Job manifest with `apiVersion: batch/v1` would only be created if you passed `--restart=OnFailure`, not `--restart=Never`. Jobs are a `batch/v1` controller abstraction used to run Pods to completion, and they require a Pod template with `restartPolicy: Never` or `OnFailure`, but the resource kind itself would be Job. Since `--restart=Never` is specified, `kubectl run` bypasses the Job controller and creates the Pod object directly.
- ✗
A Deployment manifest with apiVersion: apps/v1
Why it's wrong here
A Deployment manifest with `apiVersion: apps/v1` is wrong here because Deployments manage a ReplicaSet and provide rolling updates, and they are only generated by `kubectl run` when the default `--restart=Always` (or no explicit restart policy) is used. `--restart=Never` makes the command create a single Pod with `restartPolicy: Never`, not a Deployment. Allowing a Deployment would contradict the one-shot, no-restart intent of the command and would use the `apps/v1` API rather than `v1`.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.