KCNA Cloud Native Architecture Practice Question
A team is designing a cloud-native system that must maintain high availability across multiple cloud regions. The application uses Kubernetes clusters in each region. Which approach best ensures that the system can tolerate a full region failure while minimizing complexity?
⚠ Common exam trap
CNCF often tests the misconception that active-active with synchronous replication is always the best for high availability, but the trap here is that it introduces unnecessary complexity and cost for most use cases, while active-passive with a global load balancer offers a simpler, production-proven alternative for tolerating region failures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a global load balancer with active-passive regional failover
A global load balancer with active-passive regional failover provides a straightforward way to route traffic to a healthy secondary region when the primary fails, without the complexity of multi-region Kubernetes control planes or synchronous replication. This approach leverages DNS-based or anycast routing to detect region failure and redirect traffic, ensuring high availability while keeping the operational overhead low.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy a single Kubernetes cluster spanning all regions
Why it's wrong here
A single cluster spanning regions places its control plane across a WAN, so a region outage partitions etcd quorum and stalls scheduling cluster-wide, worsening rather than tolerating failure. It tempts teams wanting one pane of glass; that fits low-latency single-region or edge topologies, not region-failure isolation.
- ✓
Use a global load balancer with active-passive regional failover
Why this is correct
A global load balancer with active-passive regional failover keeps one region serving traffic and redirects to the standby on failure, tolerating a full region outage with far less operational complexity than active-active multi-region state replication.
- ✗
Run active-active in all regions with synchronous data replication
Why it's wrong here
Synchronous replication across regions forces every write to wait on inter-region round trips, so a failed region stalls writes or breaks quorum, and complexity rises sharply. It suits low-latency metro pairs needing zero data loss, not geographically dispersed region-failure tolerance.
- ✗
Implement manual failover procedures documented in runbooks
Why it's wrong here
Runbooks leave recovery dependent on human detection and execution, so availability during a full region failure is bounded by response time, not automation. Manual failover fits rare, planned migrations or tightly regulated changes where automated cutover is unacceptable.
Go deeper
Related to this question
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.