CKAD Application Deployment Practice Question
You want to deploy an application with zero downtime by using a blue-green deployment pattern. Which Kubernetes resources are essential for implementing this strategy?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Two Deployments (blue and green) and a Service that can switch its selector
Blue-green deployments in Kubernetes require two separate Deployments (blue and green) to maintain separate environments, and a Service that can switch its selector labels to route traffic to the active deployment. Option D is correct because it describes exactly this pattern. Option A uses a single Deployment with RollingUpdate, which is a different strategy for zero downtime but not blue-green. Option B uses StatefulSet and Headless Service, which are for stateful applications and do not support blue-green switching. Option C uses a Recreate strategy, which causes downtime by terminating all pods before creating new ones, and Ingress alone cannot switch between two deployments without additional configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A single Deployment with a RollingUpdate strategy
Why it's wrong here
A single Deployment using RollingUpdate gradually replaces old pods with new ones across the same ReplicaSet, so during the update both versions coexist and users are served by a mix of old and new pods. This provides zero-downtime as a rolling upgrade, but it does not allow an instant, atomic switch between two complete environments; there is no separate green environment held in readiness, and rollback requires initiating another rolling update. Blue-green, by contrast, keeps two fully deployed versions running and switches traffic at the routing layer, so this option cannot achieve a true blue-green deployment.
- ✗
A StatefulSet and a Headless Service
Why it's wrong here
A StatefulSet is designed for stateful workloads that need stable network identities and persistent storage per replica, and a Headless Service exposes each pod with a unique DNS name rather than load-balancing traffic. This combination solves the problem of discovering individual pods, not the problem of routing user traffic to an entire environment; it provides no selector-based mechanism to switch between two versions as a whole. Therefore, even if you ran two StatefulSets, you would need an additional Service with a mutable selector to perform blue-green switching, making this option insufficient and off-target for a stateless zero-downtime deployment.
- ✗
A Deployment with a Recreate strategy and an Ingress
Why it's wrong here
The Recreate strategy terminates every existing pod before starting any replacement pod, guaranteeing an availability gap during the deployment and failing the zero-downtime requirement. Adding an Ingress does not change that behavior because an Ingress only routes traffic to a backend Service; it does not keep a second version running or provide a way to atomically cut over between two full environments. Blue-green demands both blue and green be live concurrently, so the Recreate strategy is fundamentally incompatible with this pattern.
- ✓
Two Deployments (blue and green) and a Service that can switch its selector
Why this is correct
Blue-green deployment is implemented by two separate Deployments, one labelled as blue (current) and one as green (new), with a single Service whose selector is initially set to match the blue pods' labels. After the green Deployment is fully rolled out and verified, you update the Service's selector to point at the green pods, which instantly changes the traffic destination for all clients without any downtime. This gives you a fast, atomic switchover and an equally fast rollback by reverting the selector, because both versions remain running throughout the process.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.