KCNA Cloud Native Application Delivery Practice Question
A DevOps team wants to adopt a deployment pattern where a new version of an application is gradually rolled out to a small subset of users before full deployment. Which progressive delivery technique should they use?
⚠ Common exam trap
KCNA often tests the distinction between deployment strategies (rolling, recreate, blue-green) and progressive delivery techniques (canary, A/B, shadow), so candidates who pick 'rolling update' because it sounds gradual miss that canary is the only option giving user-subset exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Canary deployment
Canary deployment is the progressive delivery technique that routes a small percentage of live traffic to the new version while the majority continues to hit the stable version. This allows the team to observe real-user metrics (error rates, latency, business KPIs) on a limited blast radius before promoting the release to 100% of users. It is the canonical pattern for gradual, risk-controlled rollouts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Canary deployment
Why this is correct
Canary deployment routes a small percentage of live traffic to the new version, then progressively increases it while monitoring metrics. This satisfies the stem's requirement to expose only a subset of users before full rollout.
- ✗
Rolling update
Why it's wrong here
Rolling update replaces pods incrementally across the whole fleet, so every user eventually hits the new version once their replica is cycled — it cannot confine exposure to a chosen subset. It suits zero-downtime version replacement, not user-segmented validation, which canary deployment achieves through traffic splitting.
- ✗
Blue-green deployment
Why it's wrong here
Blue-green deployment switches all traffic from the blue environment to the green one at once, so no small subset of users receives the new version gradually. It suits full cutover with instant rollback, not incremental canary-style exposure.
- ✗
Recreate deployment
Why it's wrong here
Recreate deployment stops the existing version entirely before starting the new one, producing downtime and no gradual user subset, so it cannot deliver the required incremental rollout. It is tempting because it is the simplest pattern for stateless development or test environments where brief unavailability is acceptable.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.