Courseiva

KCNA Cloud Native Application Delivery Practice Question

A DevOps team wants to adopt a deployment pattern where a new version of an application is gradually rolled out to a small subset of users before full deployment. Which progressive delivery technique should they use?

⚠ Common exam trap

KCNA often tests the distinction between deployment strategies (rolling, recreate, blue-green) and progressive delivery techniques (canary, A/B, shadow), so candidates who pick 'rolling update' because it sounds gradual miss that canary is the only option giving user-subset exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Canary deployment

Canary deployment is the progressive delivery technique that routes a small percentage of live traffic to the new version while the majority continues to hit the stable version. This allows the team to observe real-user metrics (error rates, latency, business KPIs) on a limited blast radius before promoting the release to 100% of users. It is the canonical pattern for gradual, risk-controlled rollouts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Canary deployment

    Why this is correct

    Canary deployment routes a small percentage of live traffic to the new version, then progressively increases it while monitoring metrics. This satisfies the stem's requirement to expose only a subset of users before full rollout.

  • ✗

    Rolling update

    Why it's wrong here

    Rolling update replaces pods incrementally across the whole fleet, so every user eventually hits the new version once their replica is cycled — it cannot confine exposure to a chosen subset. It suits zero-downtime version replacement, not user-segmented validation, which canary deployment achieves through traffic splitting.

  • ✗

    Blue-green deployment

    Why it's wrong here

    Blue-green deployment switches all traffic from the blue environment to the green one at once, so no small subset of users receives the new version gradually. It suits full cutover with instant rollback, not incremental canary-style exposure.

  • ✗

    Recreate deployment

    Why it's wrong here

    Recreate deployment stops the existing version entirely before starting the new one, producing downtime and no gradual user subset, so it cannot deliver the required incremental rollout. It is tempting because it is the simplest pattern for stateless development or test environments where brief unavailability is acceptable.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.