KCNA Kubernetes Fundamentals Practice Question
An operations team wants a workload that runs exactly one Pod on every node in the cluster, including nodes added later, typically for log forwarding and node monitoring. Which Kubernetes workload resource is designed for this?
⚠ Common exam trap
Watch out — candidates often confuse count-based controllers such as Deployments with node-based coverage, which only DaemonSet guarantees.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DaemonSet
A DaemonSet ensures one Pod per eligible node and extends coverage automatically as nodes join, which matches the requirement for log forwarding and node monitoring. Unlike replica-count workloads, it is node-centric rather than count-centric, and it honors taints, tolerations, and node selectors to decide which nodes receive the agent Pod.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
StatefulSet
Why it's wrong here
StatefulSet provides stable network identities and ordered, persistent storage per replica, which suits databases and quorum systems rather than per-node agents. Its replicas are scheduled like any other Pod and are not tied to distinct nodes, so two replicas can land on the same node. It also does not react to node additions by creating new Pods. Using it for log forwarding would add unnecessary identity and ordering semantics.
- ✓
DaemonSet
Why this is correct
DaemonSet is purpose-built to run a copy of a Pod on every eligible node, and the DaemonSet controller automatically creates Pods for nodes that join the cluster later. It is the standard choice for node-level agents such as log shippers, monitoring exporters, and CNI or storage daemons. Taints and node selectors can scope which nodes receive the Pod, which is why control-plane nodes often need explicit tolerations.
- ✗
Job
Why it's wrong here
A Job runs Pods to completion for batch or one-off tasks and is not concerned with node coverage. Once the required number of successful completions is reached, the Job stops creating Pods. It has no mechanism to detect new nodes or to maintain a continuous per-node presence. For long-running node agents, a Job would terminate and leave nodes unmonitored, making it unsuitable here.
- ✗
Deployment
Why it's wrong here
A Deployment manages a ReplicaSet that maintains a chosen replica count across the cluster, but it does not guarantee one Pod per node and does not automatically place Pods on newly joined nodes. Its scheduler-driven placement spreads replicas by feasibility and scoring, which can concentrate multiple Pods on the same node. For per-node agents, a Deployment would require manual anti-affinity tuning and still would not scale automatically with node count.
Go deeper
Related to this question
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.