KCNA Cloud Native Architecture Practice Question
A company wants to manage its Kubernetes resources using Git as the single source of truth, with automated synchronization. Which approach should they use?
⚠ Common exam trap
The trap is confusing IaC with GitOps — candidates pick Terraform because it is 'infrastructure as code,' but GitOps specifically means continuous reconciliation of Kubernetes state from Git, which Terraform does not do.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GitOps with ArgoCD or Flux
GitOps uses Git as the declarative source of truth for cluster state, with an in-cluster agent (ArgoCD or Flux) continuously reconciling the live cluster to match the repository. This provides automated synchronization, drift detection, and auditable change history via Git commits and pull requests. It is the canonical answer when the requirement is 'Git as single source of truth with automated sync.'
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using Helm charts without version control
Why it's wrong here
Helm charts without version control give no Git history, no single source of truth and no automated reconciliation, so drift cannot be detected or corrected. Helm packages and templates manifests, and becomes relevant only when charts are stored in Git and reconciled by a GitOps agent.
- ✗
Infrastructure as Code with Terraform
Why it's wrong here
Terraform provisions and manages infrastructure through its own state file and provider APIs, so it does not continuously reconcile a cluster against Git manifests. GitOps, via Argo CD or Flux, watches the repository and syncs the live state automatically. Terraform suits provisioning cloud resources, not declarative in-cluster reconciliation.
- ✗
Using kubectl apply -f with a CI/CD pipeline
Why it's wrong here
A CI/CD pipeline running kubectl apply pushes manifests at pipeline execution, so drift after the run is never corrected and Git is not continuously reconciled. GitOps agents such as Argo CD or Flux watch the repository and automatically sync the cluster, which is the automated reconciliation the scenario requires.
- ✓
GitOps with ArgoCD or Flux
Why this is correct
GitOps treats a Git repository as the declarative source of truth, with agents such as ArgoCD or Flux continuously reconciling cluster state to match committed manifests. This delivers the automated synchronisation the company requires, detecting drift and reapplying desired configuration without manual kubectl intervention.
Go deeper
Related to this question
Learn chapter
Cluster Architecture and Lifecycle Management
Key term
GitOps
GitOps is a way to manage and automate cloud infrastructure and applications by using a Git repository as the single source of truth, where all changes are made through pull requests and automatically applied by a software agent.
Key term
ReplicaSet and Replication
A ReplicaSet ensures a specified number of identical pod instances are running at all times in Kubernetes, using replication to maintain availability and stability.
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.