Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

You want to enforce that all pods in a namespace have a minimum memory request of 100Mi and a maximum memory limit of 1Gi. Which resource should you create?

⚠ Common exam trap

Many exam-takers confuse ResourceQuota (which sets namespace-wide totals) with LimitRange (which sets per-pod constraints), or they misconfigure the LimitRange with incorrect `max`/`min` values that don't match the requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

LimitRange

A LimitRange (option D) is the correct resource because it allows you to set default, minimum, and maximum resource constraints (CPU/memory) at the namespace level, which are enforced per pod or container. In this case, you can define a LimitRange with a `min` of 100Mi and a `max` of 1Gi for memory, ensuring every pod in the namespace adheres to these bounds.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PodSecurityPolicy

    Why it's wrong here

    PodSecurityPolicy is deprecated and completely removed in Kubernetes v1.25, so it cannot be used in current clusters. Even when available, it only governed security context fields like privileged, capabilities, and SELinux settings; it never validated CPU or memory requests and limits for pods or containers. Thus it is entirely incapable of enforcing resource minimums or maximums.

  • ✗

    LimitRange with limits: - max: memory: 128Mi min: memory: 100Mi

    Why it's wrong here

    This LimitRange definition is invalid because the declared max memory of 128Mi is less than the min memory of 100Mi; Kubernetes admission will reject the resource as the max must be greater than or equal to the min. Additionally, the desired upper bound is 1Gi, not 128Mi, so even if the configuration were accepted, it would not satisfy the requirement. A correctly structured LimitRange would specify min and max values in the correct order.

  • ✗

    ResourceQuota

    Why it's wrong here

    ResourceQuota aggregates resource usage across an entire namespace, capping the total CPU and memory that all pods can collectively consume. It cannot enforce any per-pod or per-container lower or upper bound, so individual pods could specify extremely high or low requests as long as the overall quota is not exceeded. For guaranteeing each pod's resource envelope, a LimitRange is required.

  • ✓

    LimitRange

    Why this is correct

    LimitRange is the correct mechanism because it applies admission-time validation and defaulting to every pod and container created in a namespace, allowing you to set minimum and maximum request and limit values. This directly enforces that all pods have a memory request within the specified range and, if configured, that a memory limit of 1Gi is not exceeded. It is the standard Kubernetes primitive for this exact use case.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.