Courseiva
Cloud Native Architecture →mediumMultiple Choice

KCNA Cloud Native Architecture Practice Question

A company wants to manage its Kubernetes resources using Git as the single source of truth, with automated synchronization. Which approach should they use?

⚠ Common exam trap

The trap is confusing IaC with GitOps — candidates pick Terraform because it is 'infrastructure as code,' but GitOps specifically means continuous reconciliation of Kubernetes state from Git, which Terraform does not do.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

GitOps with ArgoCD or Flux

GitOps uses Git as the declarative source of truth for cluster state, with an in-cluster agent (ArgoCD or Flux) continuously reconciling the live cluster to match the repository. This provides automated synchronization, drift detection, and auditable change history via Git commits and pull requests. It is the canonical answer when the requirement is 'Git as single source of truth with automated sync.'

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Using Helm charts without version control

    Why it's wrong here

    Helm charts without version control give no Git history, no single source of truth and no automated reconciliation, so drift cannot be detected or corrected. Helm packages and templates manifests, and becomes relevant only when charts are stored in Git and reconciled by a GitOps agent.

  • ✗

    Infrastructure as Code with Terraform

    Why it's wrong here

    Terraform provisions and manages infrastructure through its own state file and provider APIs, so it does not continuously reconcile a cluster against Git manifests. GitOps, via Argo CD or Flux, watches the repository and syncs the live state automatically. Terraform suits provisioning cloud resources, not declarative in-cluster reconciliation.

  • ✗

    Using kubectl apply -f with a CI/CD pipeline

    Why it's wrong here

    A CI/CD pipeline running kubectl apply pushes manifests at pipeline execution, so drift after the run is never corrected and Git is not continuously reconciled. GitOps agents such as Argo CD or Flux watch the repository and automatically sync the cluster, which is the automated reconciliation the scenario requires.

  • ✓

    GitOps with ArgoCD or Flux

    Why this is correct

    GitOps treats a Git repository as the declarative source of truth, with agents such as ArgoCD or Flux continuously reconciling cluster state to match committed manifests. This delivers the automated synchronisation the company requires, detecting drift and reapplying desired configuration without manual kubectl intervention.

Go deeper

Related to this question

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.