KCNA Kubernetes Fundamentals Practice Question
A platform engineer is preparing a new cluster and wants each worker node to run a copy of a log-forwarding agent that must also run on control-plane nodes. Which Kubernetes workload resource should be used?
⚠ Common exam trap
The trap here is assuming that a Deployment with replicas equal to the node count will place one Pod per node, but Deployments do not guarantee per-node scheduling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DaemonSet
A DaemonSet is the only workload controller that guarantees a Pod on every eligible node, which is exactly what a per-node log-forwarding agent requires. Deployments, StatefulSets, and CronJobs do not provide per-node placement semantics, so they cannot meet the requirement of running the agent on every worker and control-plane node.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
StatefulSet with podManagementPolicy: Parallel
Why it's wrong here
A StatefulSet is designed for stateful applications that require stable network identities and persistent storage. It does not guarantee one Pod per node; Pods are scheduled independently and may be placed on the same node, so it does not satisfy the per-node agent requirement.
- ✗
Deployment with replicas equal to the number of nodes
Why it's wrong here
A Deployment manages a fixed number of replicas and does not automatically place one Pod per node. If nodes are added later, the Deployment will not schedule a Pod on the new node, so the log-forwarding agent would be missing from that node, violating the per-node requirement.
- ✗
CronJob with a schedule of every minute
Why it's wrong here
A CronJob creates Jobs on a time schedule and is intended for periodic batch tasks, not for continuously running per-node agents. It would not maintain a persistent Pod on each node, and the log-forwarding agent would not run continuously, making it unsuitable.
- ✓
DaemonSet
Why this is correct
A DaemonSet ensures that a copy of a Pod runs on every eligible node in the cluster, including newly added nodes. Because the requirement is one log-forwarding agent per node, and it must tolerate control-plane taints, a DaemonSet with appropriate tolerations is the correct workload type.
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.