Courseiva
Kubernetes Fundamentals →hardMultiple Choice

KCNA Kubernetes Fundamentals Practice Question

A pod is in CrashLoopBackOff state. 'kubectl logs pod' shows 'Error: cannot connect to database at db-service:5432'. The database Service exists and is reachable from other pods. What is the most likely cause?

⚠ Common exam trap

KCNA often tests troubleshooting logic where candidates overlook that the problem is isolated to one pod's configuration when the Service is reachable from others, instead blaming cluster-wide components like kube-proxy or the database pod.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The application's configuration has incorrect database connection details

The error 'cannot connect to database at db-service:5432' while the Service is reachable from other pods strongly indicates the application's configuration (e.g., wrong hostname, port, credentials, or database name) is incorrect. Since other pods can reach the database, the issue is isolated to this pod's config, not cluster networking or the database itself. This is a classic misconfiguration scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The kube-proxy is not functioning

    Why it's wrong here

    A broken kube-proxy would disrupt Service routing cluster-wide, yet other pods reach db-service:5432 normally, so the Service VIP path works. Kube-proxy faults are tempting because they do cause connection failures, and this would be correct if no pod anywhere in the cluster could reach the Service.

  • ✗

    The pod's resource limits are too low

    Why it's wrong here

    Insufficient CPU or memory limits cause OOMKilled or throttling, not a TCP connection error to a named Service. Resource limits are a tempting cause because they frequently produce CrashLoopBackOff, and they would be correct if logs showed the process being killed or restarted before reaching the database connection attempt.

  • ✗

    The database pod is not running

    Why it's wrong here

    Other pods reach db-service:5432 successfully, so the database itself is running and listening; a stopped database pod would break those connections too. This cause is tempting because a down backend commonly explains connection refusals, and it would be correct if every client, not just this pod, failed to connect.

  • ✓

    The application's configuration has incorrect database connection details

    Why this is correct

    Since the database Service resolves and is reachable from other pods, DNS and networking are fine; the crash stems from the application's own connection settings, such as a wrong hostname, port, or credentials in its configuration.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.