KCNA Cloud Native Application Delivery Practice Question
A CI pipeline builds a container image and tags it only as latest before pushing to a registry. A release engineer needs to deploy a specific, immutable version and be able to roll back to a known good build. What is the best practice to adopt?
⚠ Common exam trap
The trap here is believing imagePullPolicy: Always makes latest safe, when the tag itself remains mutable and unsuitable as a release identifier.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tag each image with the Git commit SHA and deploy that immutable tag.
Immutable, traceable tags let a deployment reference an exact build and make rollback deterministic. A Git commit SHA uniquely identifies the source revision, so the same tag always resolves to the same image content, unlike latest or timestamp-based tags.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Keep using latest but enable imagePullPolicy: Always on all Pods.
Why it's wrong here
Always pull policy ensures the node fetches the current latest, but latest is mutable: two deployments at different times can run different code under the same tag. Rollback becomes guesswork because there is no stable reference to a prior build, so this does not meet the immutability and rollback requirement.
- ✗
Push images to multiple registries and deploy from whichever responds fastest.
Why it's wrong here
Replicating images across registries improves availability but does nothing to solve version identity or rollback. The deployment still references a mutable or ambiguous tag, and choosing a registry at deploy time adds nondeterminism. The core problem is the tagging strategy, not registry redundancy.
- ✗
Tag images with the build timestamp and deploy the newest tag each time.
Why it's wrong here
Timestamps are unique but not tied to source code, so identifying which commit produced a given image is hard. Ordering by timestamp assumes clock consistency across builds, and rollback still requires knowing which timestamp was good. A commit SHA is a more reliable, traceable identifier for the same purpose.
- ✓
Tag each image with the Git commit SHA and deploy that immutable tag.
Why this is correct
A Git commit SHA is unique and immutable, so the same tag always refers to the same image digest. Deploying that tag makes the running version auditable and reproducible, and rolling back means redeploying a previous SHA tag. This avoids the ambiguity of latest, which can point to different images over time.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.