KCNA Kubernetes Fundamentals Practice Question
A pod is in CrashLoopBackOff state. 'kubectl logs pod' shows 'Error: cannot connect to database at db-service:5432'. The database Service exists and is reachable from other pods. What is the most likely cause?
⚠ Common exam trap
KCNA often tests troubleshooting logic where candidates overlook that the problem is isolated to one pod's configuration when the Service is reachable from others, instead blaming cluster-wide components like kube-proxy or the database pod.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The application's configuration has incorrect database connection details
The error 'cannot connect to database at db-service:5432' while the Service is reachable from other pods strongly indicates the application's configuration (e.g., wrong hostname, port, credentials, or database name) is incorrect. Since other pods can reach the database, the issue is isolated to this pod's config, not cluster networking or the database itself. This is a classic misconfiguration scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The kube-proxy is not functioning
Why it's wrong here
A broken kube-proxy would disrupt Service routing cluster-wide, yet other pods reach db-service:5432 normally, so the Service VIP path works. Kube-proxy faults are tempting because they do cause connection failures, and this would be correct if no pod anywhere in the cluster could reach the Service.
- ✗
The pod's resource limits are too low
Why it's wrong here
Insufficient CPU or memory limits cause OOMKilled or throttling, not a TCP connection error to a named Service. Resource limits are a tempting cause because they frequently produce CrashLoopBackOff, and they would be correct if logs showed the process being killed or restarted before reaching the database connection attempt.
- ✗
The database pod is not running
Why it's wrong here
Other pods reach db-service:5432 successfully, so the database itself is running and listening; a stopped database pod would break those connections too. This cause is tempting because a down backend commonly explains connection refusals, and it would be correct if every client, not just this pod, failed to connect.
- ✓
The application's configuration has incorrect database connection details
Why this is correct
Since the database Service resolves and is reachable from other pods, DNS and networking are fine; the crash stems from the application's own connection settings, such as a wrong hostname, port, or credentials in its configuration.
Go deeper
Related to this question
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.