Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

You have deployed a DaemonSet to run a logging agent on every node. After an update, the new pods are stuck in 'Pending' state. You run 'kubectl describe pod ds-pod-xxxxx' and see '0/3 nodes are available: 3 node(s) had taint {node-role.kubernetes.io/master: }, that the pod didn't tolerate'. What is the MOST likely cause?

⚠ Common exam trap

Watch out — candidates often assume DaemonSets automatically run on all nodes regardless of taints, but in reality, DaemonSets respect taints and tolerations just like any other workload, and failing to add tolerations for control-plane taints is a common misconfiguration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The DaemonSet does not have tolerations for the node taints

The error message indicates that the pod cannot be scheduled because all three nodes have a taint (specifically `node-role.kubernetes.io/master`), and the DaemonSet's pod template does not include a corresponding toleration. By default, control-plane nodes are tainted to prevent general workloads from running on them, so a DaemonSet intended to run on all nodes must include tolerations for these taints. Without tolerations, the scheduler will not place the pod on tainted nodes, leaving it in Pending state.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The DaemonSet has a nodeSelector that doesn't match any nodes

    Why it's wrong here

    A nodeSelector mismatch would make the scheduler report that no nodes matched the selector, e.g., '0/N nodes are available: N node(s) didn't match Pod's node affinity/selector.' The error here explicitly mentions taints that weren't tolerated, not a selector mismatch. Additionally, if a taint were present, even a matching nodeSelector would still block scheduling without the corresponding toleration, so the root cause is taints, not selectors.

  • ✗

    The DaemonSet uses hostNetwork which conflicts with existing pods

    Why it's wrong here

    hostNetwork changes the pod to use the host's network namespace but does not affect scheduling decisions such as taint evaluation. Port conflicts might cause bind errors after the pod starts on a node, not a Pending or unschedulable state. The scheduler's refusal is based on the node's taint and the pod's lack of a matching toleration, not any network configuration.

  • ✓

    The DaemonSet does not have tolerations for the node taints

    Why this is correct

    This is correct: DaemonSet pods, like all pods, are subject to taints and tolerations. If a node has a taint, the DaemonSet pod template must include the matching toleration; otherwise, the scheduler will leave the pod Pending with an event like '0/N nodes are available: N node(s) had taint {key=value:NoSchedule}, that the pod didn't tolerate.' The DaemonSet controller can only create pods; it cannot bypass the scheduler's taint rules.

  • ✗

    The nodes are cordoned

    Why it's wrong here

    Cordoning a node marks it unschedulable via the node's unschedulable field, which the scheduler reports as 'node(s) cordoned' or 'node(s) were unschedulable.' That is distinctly different from taint-related messages. Also, cordoned nodes are often tainted as well, but the error specifically uses taint language, so cordoning alone would not produce this exact scheduling message.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.