Courseiva
Kubernetes Fundamentals →mediumMultiple Choice

KCNA Kubernetes Fundamentals Practice Question

A cluster administrator needs to run a critical system daemon that must continue running even when a node is marked as unschedulable for maintenance. The DaemonSet Pods should tolerate the node's taint. Which taint should the DaemonSet Pod tolerate to achieve this?

⚠ Common exam trap

The trap here is assuming that tolerating not-ready or unreachable taints would allow Pods to run on cordoned nodes, but only the unschedulable taint is added during cordon.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

node.kubernetes.io/unschedulable

Cordoning a node adds the taint node.kubernetes.io/unschedulable:NoSchedule. To keep DaemonSet Pods running on that node during maintenance, the Pod template must tolerate this taint. The other taints represent different node conditions and do not address the unschedulable state.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    node.kubernetes.io/unreachable

    Why it's wrong here

    The taint node.kubernetes.io/unreachable is added when the node controller cannot reach the node, indicating a potential network partition. Tolerating this taint would let Pods run on unreachable nodes, which is dangerous for most workloads. It does not relate to the unschedulable state caused by cordoning a node for maintenance.

  • ✓

    node.kubernetes.io/unschedulable

    Why this is correct

    When a node is cordoned using kubectl cordon, Kubernetes adds the taint node.kubernetes.io/unschedulable:NoSchedule. To allow DaemonSet Pods to continue running on that node, the Pod template must include a toleration for this taint. This is the correct taint to tolerate for maintenance scenarios where you want existing Pods to keep running but prevent new scheduling.

  • ✗

    node.kubernetes.io/not-ready

    Why it's wrong here

    The taint node.kubernetes.io/not-ready is automatically added when a node is not ready, often due to network issues or kubelet problems. Tolerating this taint would allow Pods to run on not-ready nodes, but it does not address the unschedulable condition set by kubectl cordon. The unschedulable taint is specifically node.kubernetes.io/unschedulable.

  • ✗

    node.kubernetes.io/memory-pressure

    Why it's wrong here

    The taint node.kubernetes.io/memory-pressure is added when a node is low on memory. Tolerating this taint would allow Pods to be scheduled on memory-constrained nodes, which could lead to OOM kills. It is not related to the unschedulable state from cordoning. For maintenance, the unschedulable taint is the relevant one.

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.