KCNA Container Orchestration Practice Question
A team runs a stateless web application and wants to update its container image with zero downtime while gradually shifting traffic to the new version. They also need the ability to pause the rollout, inspect the new Pods, and then resume. Which Kubernetes workload and strategy best supports this workflow?
⚠ Common exam trap
The trap here is assuming that pause/resume and gradual traffic shifting are generic to all workload controllers, when they are specifically supported by Deployment rollouts with the RollingUpdate strategy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Deployment using the RollingUpdate strategy with maxSurge and maxUnavailable.
A Deployment with the RollingUpdate strategy is the standard Kubernetes mechanism for zero-downtime, incremental updates of stateless applications. maxSurge and maxUnavailable let the team tune how many extra and unavailable Pods are allowed during the transition. The 'kubectl rollout pause' and 'kubectl rollout resume' commands support inspecting the new revision before completing the rollout.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A StatefulSet with the OnDelete update strategy.
Why it's wrong here
A StatefulSet is intended for stateful applications requiring stable identities and ordered operations. The OnDelete strategy updates Pods only when they are manually deleted, which does not provide automated gradual traffic shifting for a stateless web app. It lacks the pause/resume rollout workflow associated with Deployments.
- ✗
A CronJob scheduled to delete old Pods at a fixed interval.
Why it's wrong here
A CronJob runs time-based batch tasks and has no concept of maintaining a desired replica count or performing a rolling version transition. Deleting old Pods on a schedule would create outages rather than a controlled rollout. It also provides no mechanism to pause or resume a deployment revision.
- ✓
A Deployment using the RollingUpdate strategy with maxSurge and maxUnavailable.
Why this is correct
A Deployment with the RollingUpdate strategy replaces Pods incrementally while keeping the application available, and its maxSurge and maxUnavailable settings control the pace of the transition. The rollout can be paused with 'kubectl rollout pause', inspected, and resumed with 'kubectl rollout resume', exactly matching the requested workflow.
- ✗
A Job with parallelism set to the desired replica count.
Why it's wrong here
A Job runs Pods to completion for batch-style tasks and does not maintain a long-running desired state for a web application. It has no rolling update or pause/resume capability for gradual traffic shifting. Using a Job would terminate the application when the task finishes and cannot provide zero-downtime version transitions.
Go deeper
Related to this question
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.