Courseiva

KCNA Cloud Native Application Delivery Practice Question

A CI pipeline builds a container image and tags it only as latest before pushing to a registry. A release engineer needs to deploy a specific, immutable version and be able to roll back to a known good build. What is the best practice to adopt?

⚠ Common exam trap

The trap here is believing imagePullPolicy: Always makes latest safe, when the tag itself remains mutable and unsuitable as a release identifier.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tag each image with the Git commit SHA and deploy that immutable tag.

Immutable, traceable tags let a deployment reference an exact build and make rollback deterministic. A Git commit SHA uniquely identifies the source revision, so the same tag always resolves to the same image content, unlike latest or timestamp-based tags.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Keep using latest but enable imagePullPolicy: Always on all Pods.

    Why it's wrong here

    Always pull policy ensures the node fetches the current latest, but latest is mutable: two deployments at different times can run different code under the same tag. Rollback becomes guesswork because there is no stable reference to a prior build, so this does not meet the immutability and rollback requirement.

  • ✗

    Push images to multiple registries and deploy from whichever responds fastest.

    Why it's wrong here

    Replicating images across registries improves availability but does nothing to solve version identity or rollback. The deployment still references a mutable or ambiguous tag, and choosing a registry at deploy time adds nondeterminism. The core problem is the tagging strategy, not registry redundancy.

  • ✗

    Tag images with the build timestamp and deploy the newest tag each time.

    Why it's wrong here

    Timestamps are unique but not tied to source code, so identifying which commit produced a given image is hard. Ordering by timestamp assumes clock consistency across builds, and rollback still requires knowing which timestamp was good. A commit SHA is a more reliable, traceable identifier for the same purpose.

  • ✓

    Tag each image with the Git commit SHA and deploy that immutable tag.

    Why this is correct

    A Git commit SHA is unique and immutable, so the same tag always refers to the same image digest. Deploying that tag makes the running version auditable and reproducible, and rolling back means redeploying a previous SHA tag. This avoids the ambiguity of latest, which can point to different images over time.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.