Courseiva
Kubernetes Fundamentals →hardMultiple Choice

KCNA Kubernetes Fundamentals Practice Question

An administrator runs `kubectl taint nodes node1 dedicated=gpu:NoSchedule` and then creates a Pod with the toleration `key: dedicated, operator: Equal, value: gpu, effect: NoSchedule`. The Pod is scheduled onto node1, but the administrator expected the taint to repel all Pods without a matching toleration. Which statement explains why the Pod was still placed on node1?

⚠ Common exam trap

The trap here is treating a taint as an absolute prohibition, when a matching toleration explicitly permits scheduling onto the tainted node.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The toleration matches the taint, so the scheduler is allowed to place the Pod on node1; taints repel only Pods that do not tolerate them.

Taints and tolerations work as a pair: a taint repels Pods that lack a matching toleration, but a Pod that tolerates the taint is allowed onto the node. Because the Pod's toleration matched the taint's key, value, and effect, the scheduler correctly placed it on node1. The administrator's mental model omitted the effect of the toleration, which is the intended escape hatch.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The taint effect `NoSchedule` only applies to Pods created in the kube-system namespace, so user Pods are unaffected.

    Why it's wrong here

    Taint effects are not namespace-scoped; they apply to all Pods unless the Pod has a matching toleration or the taint is removed. Control-plane nodes often carry taints, and system Pods tolerate them, but the effect itself is global to the node. This option invents a namespace restriction that does not exist in Kubernetes taint behavior.

  • ✓

    The toleration matches the taint, so the scheduler is allowed to place the Pod on node1; taints repel only Pods that do not tolerate them.

    Why this is correct

    A taint with effect `NoSchedule` prevents scheduling of Pods that do not have a matching toleration. The Pod in the scenario has an Equal toleration for key `dedicated`, value `gpu`, and effect `NoSchedule`, which matches the taint exactly. Therefore the scheduler treats the node as eligible and places the Pod there. The administrator's expectation was incorrect because the Pod is not repelled.

  • ✗

    Taints are only enforced during eviction, not during initial scheduling, so any Pod can land on a tainted node.

    Why it's wrong here

    Taints are enforced by the scheduler at scheduling time for `NoSchedule` and `NoExecute`, and `PreferNoSchedule` is a soft preference. They are not limited to eviction. A Pod without a matching toleration would be filtered out by the TaintToleration plugin. This option misstates the enforcement point and would incorrectly suggest taints have no scheduling effect.

  • ✗

    The toleration must use `operator: Exists` to match a taint with a value; `operator: Equal` never matches when a value is present.

    Why it's wrong here

    The `Equal` operator matches when both key and value are equal to the taint's key and value, and the effect matches. The `Exists` operator matches any value for the given key. Both are valid. Claiming that `Equal` never matches when a value is present is false and would lead to unnecessary changes to a correctly formed toleration.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.