CKAD Practice Question: Application Environment, Configuration and Security
You want to restrict total memory usage in a namespace to 10 Gi. Which resource should you create?
⚠ Common exam trap
CNCF often tests the distinction between per-container limits (LimitRange) and aggregate namespace limits (ResourceQuota), leading candidates to mistakenly choose LimitRange when the question explicitly asks for total namespace-wide restrictions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ResourceQuota
A ResourceQuota is the correct Kubernetes object to enforce aggregate resource consumption limits at the namespace level. By defining a ResourceQuota with `spec.hard.memory: 10Gi`, you restrict the total memory requested and used by all pods in that namespace to 10 GiB. This directly meets the requirement to limit total memory usage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ResourceQuota
Why this is correct
A ResourceQuota is an admission controller resource that sets a hard ceiling on aggregate resource usage in a namespace. By configuring spec.hard.requests.memory to 10Gi, the Kubernetes API server sums the memory requests of all existing and newly created Pods in that namespace and rejects any new Pod that would push the total over 10Gi. This directly satisfies the requirement to restrict total memory usage across all Pods in the namespace.
- ✗
PodDisruptionBudget
Why it's wrong here
A PodDisruptionBudget is a policy object that limits the number of voluntary disruptions to a set of Pods, typically to ensure availability during node drains or maintenance. It defines minAvailable or maxUnavailable in terms of Pod counts, not resource quantities, and it has no awareness of memory requests or limits. Therefore, it cannot restrict the total memory consumption of a namespace to a value like 10Gi.
- ✗
LimitRange
Why it's wrong here
A LimitRange enforces per-container or per-Pod minimum and maximum resource values, as well as default requests and limits at creation time. It validates each individual Pod in isolation, so a container may consume up to the maximum allowed but multiple Pods in the same namespace can still collectively exceed 10Gi if they are all maximally sized. Because it lacks any aggregate view of the namespace, a LimitRange alone cannot cap total memory usage.
- ✗
NetworkPolicy
Why it's wrong here
A NetworkPolicy governs traffic flows between Pods, namespaces, and external endpoints by using selectors, ports, and IP CIDR rules. It operates entirely at the CNI layer to allow or deny network packets and has no mechanism to measure, limit, or enforce memory consumption. Since the question is about restricting memory usage to 10Gi, a NetworkPolicy is completely unrelated to the desired constraint.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.