Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

You want to restrict total memory usage in a namespace to 10 Gi. Which resource should you create?

⚠ Common exam trap

CNCF often tests the distinction between per-container limits (LimitRange) and aggregate namespace limits (ResourceQuota), leading candidates to mistakenly choose LimitRange when the question explicitly asks for total namespace-wide restrictions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ResourceQuota

A ResourceQuota is the correct Kubernetes object to enforce aggregate resource consumption limits at the namespace level. By defining a ResourceQuota with `spec.hard.memory: 10Gi`, you restrict the total memory requested and used by all pods in that namespace to 10 GiB. This directly meets the requirement to limit total memory usage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ResourceQuota

    Why this is correct

    A ResourceQuota is an admission controller resource that sets a hard ceiling on aggregate resource usage in a namespace. By configuring spec.hard.requests.memory to 10Gi, the Kubernetes API server sums the memory requests of all existing and newly created Pods in that namespace and rejects any new Pod that would push the total over 10Gi. This directly satisfies the requirement to restrict total memory usage across all Pods in the namespace.

  • ✗

    PodDisruptionBudget

    Why it's wrong here

    A PodDisruptionBudget is a policy object that limits the number of voluntary disruptions to a set of Pods, typically to ensure availability during node drains or maintenance. It defines minAvailable or maxUnavailable in terms of Pod counts, not resource quantities, and it has no awareness of memory requests or limits. Therefore, it cannot restrict the total memory consumption of a namespace to a value like 10Gi.

  • ✗

    LimitRange

    Why it's wrong here

    A LimitRange enforces per-container or per-Pod minimum and maximum resource values, as well as default requests and limits at creation time. It validates each individual Pod in isolation, so a container may consume up to the maximum allowed but multiple Pods in the same namespace can still collectively exceed 10Gi if they are all maximally sized. Because it lacks any aggregate view of the namespace, a LimitRange alone cannot cap total memory usage.

  • ✗

    NetworkPolicy

    Why it's wrong here

    A NetworkPolicy governs traffic flows between Pods, namespaces, and external endpoints by using selectors, ports, and IP CIDR rules. It operates entirely at the CNI layer to allow or deny network packets and has no mechanism to measure, limit, or enforce memory consumption. Since the question is about restricting memory usage to 10Gi, a NetworkPolicy is completely unrelated to the desired constraint.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.