Courseiva
Container Orchestration →hardMultiple Select

KCNA Container Orchestration Practice Question

A platform team must ensure that a critical StatefulSet named ledger in the finance namespace always has at least two Pods available during voluntary disruptions such as node drains, and that Pods are spread across different nodes. Which two resources or settings should they configure? (Choose two.)

⚠ Common exam trap

The trap here is treating PriorityClass or ResourceQuota as availability guarantees, when only a PodDisruptionBudget constrains voluntary evictions and a topologySpreadConstraint enforces node spreading.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A PodDisruptionBudget in the finance namespace with minAvailable: 2 and a selector matching the ledger Pods.

A PodDisruptionBudget with minAvailable: 2 protects the StatefulSet during voluntary disruptions by blocking evictions that would drop below two available Pods. A topologySpreadConstraint keyed on kubernetes.io/hostname with DoNotSchedule enforces placement on separate nodes, which supports both resilience and the availability target. NetworkPolicy, ResourceQuota, and PriorityClass address traffic control, resource limits, and scheduling priority rather than the required availability and spread guarantees.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A ResourceQuota in the finance namespace limiting CPU and memory requests.

    Why it's wrong here

    A ResourceQuota caps aggregate resource consumption in a namespace and can affect whether new Pods are admitted, but it does not guarantee availability during voluntary disruptions or enforce node spreading. It could even prevent scale-up if the quota is exhausted. It is unrelated to the availability and placement requirements described.

  • ✓

    A PodDisruptionBudget in the finance namespace with minAvailable: 2 and a selector matching the ledger Pods.

    Why this is correct

    A PodDisruptionBudget constrains voluntary disruptions by requiring that at least the specified number of Pods remain available. With minAvailable: 2 and a selector for the ledger Pods, node drains and other voluntary evictions will be blocked or delayed until two Pods are healthy. This directly satisfies the availability requirement during voluntary disruptions.

  • ✗

    A NetworkPolicy in the finance namespace that allows ingress only from the ledger Pods.

    Why it's wrong here

    A NetworkPolicy controls network traffic between Pods and does not influence scheduling, node placement, or voluntary disruption behavior. It would not keep two Pods available during a drain, nor would it spread Pods across nodes. It addresses a different concern, namely network segmentation, so it is not part of this solution.

  • ✓

    A topologySpreadConstraint on the StatefulSet Pod template with topologyKey kubernetes.io/hostname and whenUnsatisfiable: DoNotSchedule.

    Why this is correct

    A topologySpreadConstraint with topologyKey kubernetes.io/hostname spreads Pods across distinct nodes. Using whenUnsatisfiable: DoNotSchedule makes the scheduler refuse to place a Pod if the spread rule cannot be met, which enforces node diversity. This complements the PodDisruptionBudget by keeping the replicas on separate nodes.

  • ✗

    A PriorityClass assigned to the ledger Pods with a high value.

    Why it's wrong here

    A PriorityClass influences scheduling order and preemption when resources are scarce, helping critical Pods get scheduled first. It does not prevent voluntary evictions during a drain, nor does it spread Pods across nodes. While useful for critical workloads, it does not satisfy either stated requirement on its own.

About these practice questions

This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.