KCNA Cloud Native Architecture Practice Question
A team is implementing a multi-cloud strategy to avoid vendor lock-in. Which Kubernetes feature is most helpful for abstracting the underlying cloud provider?
⚠ Common exam trap
KCNA often tests whether candidates confuse a specific API object (Service, ConfigMap, Namespace) with the API itself as the abstraction layer — the trap is picking a familiar resource instead of the unifying API.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kubernetes API
The Kubernetes API is the abstraction layer that decouples workloads from any specific cloud provider — manifests, controllers, and clients interact with the API server, not with AWS, GCP, or Azure APIs directly. This portability is what enables multi-cloud and avoids vendor lock-in. While Services, ConfigMaps, and Namespaces are API objects, the API itself is the unifying abstraction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Services
Why it's wrong here
Services provide stable virtual IPs and load balancing for pods, but their implementation relies on provider-specific load balancers and networking, so the abstraction does not remove cloud lock-in. They are tempting because they decouple pod addressing, which is their real role.
- ✗
ConfigMaps
Why it's wrong here
ConfigMaps store non-confidential configuration as key-value data for pods; they hold no provider-facing networking or infrastructure abstraction, so multi-cloud portability is unaffected. They are tempting because they externalise configuration from images, which is their actual purpose.
- ✗
Namespaces
Why it's wrong here
Namespaces partition objects within a single cluster for multi-tenancy and resource quotas; they do not abstract cloud provider APIs, so workloads remain tied to provider-specific nodes, storage and load balancers. They are tempting because they isolate teams and environments cleanly, which is their actual purpose.
- ✓
Kubernetes API
Why this is correct
The Kubernetes API provides a consistent declarative interface that abstracts underlying infrastructure, so workloads defined against it remain portable across clouds. This decoupling from provider-specific APIs directly satisfies the vendor lock-in avoidance goal of the multi-cloud strategy.
Go deeper
Related to this question
Learn chapter
Kubernetes API and Core Objects
Key term
Namespaces
A Namespace in Kubernetes is a virtual cluster within a physical cluster that allows you to organize and isolate resources, like an apartment building with separate units for different tenants.
Key term
ReplicaSet and Replication
A ReplicaSet ensures a specified number of identical pod instances are running at all times in Kubernetes, using replication to maintain availability and stability.
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.