Courseiva
Container Orchestration →mediumMultiple Choice

KCNA Container Orchestration Practice Question

A cluster administrator needs to run a node-level log-shipping agent on every node, including nodes added later, and wants the agent to tolerate the control-plane taint. Which workload API object is the most appropriate choice?

⚠ Common exam trap

The trap here is treating a Deployment or ReplicaSet as a one-Pod-per-node mechanism, when only a DaemonSet automatically maintains node-level coverage including newly added nodes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A DaemonSet with a toleration for the control-plane taint.

A DaemonSet is designed for node-level agents such as log shippers, monitoring exporters, and CNI plugins. It places one Pod on each node that matches scheduling constraints and automatically covers nodes that join later. Combining it with a toleration for the control-plane taint allows the agent to run on control-plane nodes as well, satisfying the administrator's full-coverage requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A StatefulSet with podAntiAffinity requiring one Pod per node.

    Why it's wrong here

    A StatefulSet provides stable network identities and ordered scaling for stateful workloads, not one-Pod-per-node distribution. Pod anti-affinity can spread replicas but does not automatically add a Pod when a new node joins, and it does not address the control-plane taint without separate tolerations. It is the wrong abstraction for a node agent.

  • ✗

    A ReplicaSet with replicas equal to the current node count.

    Why it's wrong here

    A ReplicaSet maintains a fixed replica count but does not tie Pods to individual nodes or react to cluster scaling. If a node is added, the replica count must be manually updated, and scheduling is not guaranteed to place a Pod on every node. It also lacks built-in toleration handling for the control-plane taint.

  • ✗

    A Deployment with a nodeSelector for each existing node name.

    Why it's wrong here

    A Deployment manages a fixed number of replicas and does not automatically schedule one Pod per node. Using nodeSelector with explicit node names also fails when nodes are added later, because the selector list is static. It cannot guarantee coverage of new nodes and does not natively tolerate the control-plane taint without extra configuration.

  • ✓

    A DaemonSet with a toleration for the control-plane taint.

    Why this is correct

    A DaemonSet ensures that a copy of a Pod runs on every eligible node and automatically schedules new Pods onto nodes that join the cluster. Adding a toleration for the control-plane taint lets the agent also run on control-plane nodes. This directly matches the requirement for continuous node-level coverage across existing and future nodes.

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.