Courseiva
Kubernetes Fundamentals →mediumMultiple Choice

KCNA Kubernetes Fundamentals Practice Question

A cluster administrator needs to run a node-level logging agent on every node, including nodes added later. The agent must collect logs from the host filesystem and must run even if a node is cordoned. Which workload resource should be used?

⚠ Common exam trap

The trap here is choosing a Deployment with a nodeSelector, which can place pods on labeled nodes but does not guarantee one pod per node or cover nodes added later.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A DaemonSet

DaemonSets are purpose-built for per-node workloads. The DaemonSet controller creates a pod on each eligible node and adds new pods when nodes join the cluster. Its default tolerations allow the pods to run on nodes that are unschedulable or carry common taints, which is essential for infrastructure agents like log shippers, monitoring exporters, and CNI plugins that must operate everywhere.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A StatefulSet with one replica per node

    Why it's wrong here

    A StatefulSet provides stable network identities and persistent storage for stateful applications, but it does not automatically spread pods across every node. It requires manual scaling and does not react to new nodes by placing a pod there. It also lacks the default tolerations that let node agents run on cordoned or tainted nodes, so it is unsuitable for this logging use case.

  • ✗

    A Job with a parallelism equal to the number of nodes

    Why it's wrong here

    A Job runs pods to completion and is designed for batch or one-time tasks, not for continuously running node agents. Its parallelism controls how many pods run concurrently, but it does not guarantee one pod per node or respond to nodes joining the cluster. Log collection requires a long-running process, so a Job would terminate and stop collecting logs.

  • ✗

    A Deployment with a nodeSelector matching each node's label

    Why it's wrong here

    A Deployment manages a fixed number of replicas and does not automatically place one pod on every node. Even with a nodeSelector, the ReplicaSet controller only ensures the requested replica count, so some nodes may have no logging agent and new nodes are not guaranteed coverage. It also does not tolerate all taints by default, so cordoned or special-purpose nodes could be missed.

  • ✓

    A DaemonSet

    Why this is correct

    A DaemonSet ensures that a copy of a pod runs on every node in the cluster, and it automatically schedules pods onto nodes added later. Its pods are created by the DaemonSet controller with tolerations that allow them to run on nodes that are cordoned or have standard taints, making it the correct choice for node-level agents such as log collectors.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.