Courseiva
Kubernetes Fundamentals →hardMultiple Choice

KCNA Kubernetes Fundamentals Practice Question

A platform engineer is designing a multi-tenant cluster. They want to ensure that a specific team's workloads can only be scheduled onto nodes labeled `team=blue`, and that workloads from other teams cannot be scheduled there. The team's Pods should not run on any other nodes. Which combination of Kubernetes features should the engineer use to enforce this?

⚠ Common exam trap

The trap here is thinking that nodeSelector alone provides isolation, when it only attracts Pods and does not repel others from the node.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

nodeSelector on the Pods plus taints and tolerations on the nodes.

Dedicated node pools are implemented by combining attraction and repulsion. nodeSelector or nodeAffinity pulls the team's Pods toward nodes labeled team=blue, while a taint on those nodes, paired with a toleration on the Pods, keeps other workloads away. Neither feature alone provides full isolation: nodeSelector without a taint lets others share the node, and a taint without nodeSelector lets the team's Pods land elsewhere.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    NetworkPolicy applied to the team's namespace with a node selector.

    Why it's wrong here

    NetworkPolicy governs allowed ingress and egress traffic between Pods and external endpoints; it has no concept of node selection. It cannot influence the scheduler. Using NetworkPolicy here would not restrict placement and would leave the node isolation requirement unmet, even though it is valuable for traffic isolation.

  • ✗

    Pod affinity rules alone, using requiredDuringSchedulingIgnoredDuringExecution.

    Why it's wrong here

    Pod affinity controls co-location of Pods relative to other Pods, not exclusive node ownership. It can attract the team's Pods toward each other, but it does not prevent other teams' Pods from being scheduled on the same nodes. Without a taint or node affinity constraint, other workloads can still land on team=blue nodes, breaking isolation.

  • ✓

    nodeSelector on the Pods plus taints and tolerations on the nodes.

    Why this is correct

    nodeSelector or nodeAffinity attracts the team's Pods to nodes labeled team=blue, while a taint such as dedicated=blue:NoSchedule on those nodes repels Pods that lack the matching toleration. Together they provide both attraction and repulsion, ensuring only the intended Pods land on those nodes and that those Pods go nowhere else. This is the standard pattern for dedicated node pools.

  • ✗

    ResourceQuota and LimitRange applied to the team's namespace.

    Why it's wrong here

    ResourceQuota limits aggregate resource consumption and object counts per namespace, and LimitRange sets default or min/max resource values per object. Neither controls which nodes a Pod can be scheduled onto. They are useful for fairness and preventing resource exhaustion, but they do not provide node-level placement isolation.

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.