Courseiva
Container Orchestration →mediumMultiple Choice

KCNA Container Orchestration Practice Question

A company wants to adopt immutable infrastructure for its containerized applications. Which practice BEST exemplifies immutability?

⚠ Common exam trap

Watch out — candidates often confuse immutability with automation, thinking that any automated update (like a config management tool) is acceptable, when in fact immutability in Kubernetes requires that no changes are made to running containers — only new images are deployed via rolling updates or similar mechanisms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

When a container fails, the orchestrator terminates it and launches a new container from the same image

Immutable infrastructure means that once a container is deployed from a specific image, it is never modified in place. When a container fails, the orchestrator (e.g., Kubernetes) terminates it and launches a new container from the same image, ensuring consistency and reproducibility. This approach eliminates configuration drift and aligns with the principle that all changes should be made by rebuilding the image, not by altering running instances.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Developers use kubectl exec to change environment variables in a running pod

    Why it's wrong here

    Using kubectl exec to mutate a running pod changes live state in place, which is the opposite of immutability; immutable infrastructure replaces instances rather than editing them. It is tempting because exec is a legitimate debugging and troubleshooting tool, but it is not a deployment mechanism for configuration changes.

  • ✓

    When a container fails, the orchestrator terminates it and launches a new container from the same image

    Why this is correct

    Immutability means containers are never patched or modified in place. Terminating the failed container and starting a fresh one from the identical image preserves the immutable artefact, satisfying the constraint that running instances are replaced rather than mutated.

  • ✗

    A configuration management tool runs periodically to ensure containers are up-to-date

    Why it's wrong here

    Periodic configuration management that keeps containers up-to-date mutates running instances, which is mutable, convergent configuration rather than immutable replacement. It is tempting because such tools are legitimate for managing long-lived servers, but immutable infrastructure rebuilds and redeploys images instead of continuously correcting live containers.

  • ✗

    An operator logs into a running container and applies a security patch with apt-get update

    Why it's wrong here

    Patching a running container in place mutates a deployed artefact, violating immutability; the correct approach rebuilds the image and redeploys. It is tempting because applying security patches is genuinely necessary, but that must happen by publishing a new image version, not by logging into a live container.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.