KCNA Container Orchestration Practice Question
A container image built using a Dockerfile with multiple layers is stored in a registry. When a node pulls this image, which statement about layers is true?
⚠ Common exam trap
The KCNA exam often tests the misconception that layers are merged or streamed, but the correct behavior is that each layer is a separate, immutable blob that is cached independently and reused across images.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Layers that are already cached on the node are reused and only new layers are downloaded
Container images are composed of read-only layers, each representing a set of filesystem changes. When a node pulls an image, the container runtime (e.g., containerd or CRI-O) checks its local layer cache against the manifest's layer digests (SHA256 hashes). Layers already present locally are reused, and only missing layers are downloaded from the registry, which optimizes bandwidth and storage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Layers that are already cached on the node are reused and only new layers are downloaded
Why this is correct
Cached layers are content-addressed by digest, so the node verifies each layer locally and fetches only digests absent from its local store. This satisfies the stem's constraint: a multi-layer image pull avoids re-downloading unchanged layers, transferring just the new layers.
- ✗
Layers are merged into a single layer before download
Why it's wrong here
Layers remain individually addressable in the registry and are pulled as discrete blobs; merging happens only at the container filesystem level via overlay mounts, never before download. It is tempting because Dockerfiles squash layers during builds, but that is a build-time export step, not registry storage.
- ✗
All layers must be downloaded each time the image is pulled
Why it's wrong here
Layers already present in the node's local content store are reused, so a pull only downloads missing blobs. It is tempting because the first pull of a fresh image does fetch every layer, but subsequent pulls with shared base layers skip them, which is the point of layer deduplication.
- ✗
Only the topmost layer is downloaded; lower layers are streamed from the registry
Why it's wrong here
Every non-cached layer must be fetched as its own blob; the registry serves each layer separately and no streaming of lower layers occurs. It is tempting because lazy-pulling runtimes such as Stargz and Nydus fetch layers on demand, but that requires a snapshotter configured for lazy pulling, not the default behaviour.
Go deeper
Related to this question
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.