Courseiva
Container Orchestration →mediumMultiple Choice

KCNA Container Orchestration Practice Question

A Kubernetes cluster runs a DaemonSet named 'node-agent' that must run on every node, including the control-plane node. The control-plane node has a taint 'node-role.kubernetes.io/control-plane:NoSchedule'. The DaemonSet currently does not schedule pods on the control-plane node. Which change to the DaemonSet spec will ensure its pods run on the control-plane node?

⚠ Common exam trap

The trap here is assuming that DaemonSets automatically tolerate all taints, including control-plane taints, when in fact explicit tolerations are required for tainted nodes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a toleration for the taint 'node-role.kubernetes.io/control-plane:NoSchedule' to the DaemonSet's pod template.

Taints and tolerations work together to control scheduling. A taint on a node repels pods that do not tolerate it. To run DaemonSet pods on a tainted node such as a control-plane node, the pod template must include a toleration for that specific taint. Other scheduling controls like node selectors or priority classes do not override taints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add a toleration for the taint 'node-role.kubernetes.io/control-plane:NoSchedule' to the DaemonSet's pod template.

    Why this is correct

    Taints repel pods unless the pod has a matching toleration. Adding a toleration for the control-plane taint allows the DaemonSet pods to be scheduled onto that node. DaemonSets do not automatically tolerate control-plane taints, so this explicit toleration is required to run on every node including the control-plane node.

  • ✗

    Add a node selector to the DaemonSet's pod template that matches the control-plane node's labels.

    Why it's wrong here

    A node selector restricts pods to nodes with specific labels, but it does not overcome a taint. The control-plane node's taint still repels pods without a toleration. Adding only a node selector would not allow scheduling on the tainted node; a toleration is also required.

  • ✗

    Increase the DaemonSet's 'spec.template.spec.priorityClassName' to a higher priority class.

    Why it's wrong here

    Priority classes influence scheduling order and preemption but do not bypass taints. A higher priority does not grant permission to schedule on a tainted node. Without a toleration, the DaemonSet pods remain unschedulable on the control-plane node regardless of priority.

  • ✗

    Set the DaemonSet's update strategy to 'OnDelete' so that pods are only created when nodes are added.

    Why it's wrong here

    The update strategy controls how pods are updated when the DaemonSet spec changes, not where they are scheduled. 'OnDelete' means new pods are only created after old ones are manually deleted, which is unrelated to taint toleration and will not cause pods to be scheduled on the tainted control-plane node.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.