CKS Supply Chain Security Practice Question
A pod is stuck in Pending state. 'kubectl describe pod' shows the event: '0/4 nodes are available: 1 node had taint {node-role.kubernetes.io/control-plane: }, that the pod didn't tolerate, 3 Insufficient memory.' The pod YAML does not specify any tolerations. Which command would allow the pod to schedule on the control-plane node?
⚠ Common exam trap
A common mix-up: candidates choose to remove the taint (Option A) because it seems like a quick fix, but the CKS exam emphasizes security best practices—taints are a security mechanism to isolate control-plane components, and removing them globally is insecure and unnecessary when a toleration can be added to the specific pod.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Edit the pod YAML to add tolerations for node-role.kubernetes.io/control-plane
The pod is failing to schedule on the control-plane node due to the `node-role.kubernetes.io/control-plane` taint, which by default prevents pods without a matching toleration from being scheduled. Since the pod YAML does not specify any tolerations, editing it to add a toleration for that taint (e.g., `tolerations: - key: node-role.kubernetes.io/control-plane operator: Exists`) explicitly allows the pod to run on the control-plane node, resolving the Pending state.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl taint nodes control-plane node-role.kubernetes.io/control-plane-
Why it's wrong here
Removing the taint with the trailing dash (`kubectl taint nodes control-plane node-role.kubernetes.io/control-plane-`) unsets the node's NoSchedule taint, which is a cluster-wide change affecting all future scheduling decisions. This deliberately weakens the security boundary of the control-plane node by allowing any pod without a matching toleration to be placed there, and it does not target the specific pod or workload; the correct approach is to add a toleration to the pod spec, not diminish the node's protections.
- ✗
kubectl cordon control-plane
Why it's wrong here
Cordoning a node marks it as unschedulable, which actually prevents new pods (including the stuck one) from being scheduled there entirely. This is a maintenance or node-drain operation and does not remove or modify any existing taints; in fact, it adds a second scheduling barrier, ensuring the pod remains Pending. It is the opposite of what is needed to place a workload on the control-plane node.
- ✓
Edit the pod YAML to add tolerations for node-role.kubernetes.io/control-plane
Why this is correct
Control-plane nodes in kubeadm clusters carry the taint `node-role.kubernetes.io/control-plane:NoSchedule`, so a pod must include a matching toleration such as `tolerations: - key: node-role.kubernetes.io/control-plane, operator: Exists, effect: NoSchedule` before the scheduler will consider that node. Adding this toleration to the pod's YAML makes it explicitly accept the taint, allowing the pod to be placed on the control-plane node. This is the targeted, least-invasive solution because it only affects the workload that needs to run there, without altering node-level security settings.
- ✗
kubectl delete pod --all
Why it's wrong here
Deleting all pods does not change taints, tolerations, or scheduler constraints, so the replacement pods will be created with the same missing tolerations and will become Pending again immediately. This action is also highly disruptive because it terminates every workload in the namespace or cluster, including healthy ones, and it fails to address the root cause: the pod lacks the toleration required to schedule on the tainted control-plane node.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.