Courseiva

KCNA · domain

Cloud Native Architecture

Cloud Native Architecture covers the design principles behind scalable, resilient, loosely coupled systems and the Kubernetes primitives that realize them. Questions test your grasp of microservices, containers, declarative infrastructure, and multi-region high availability, plus which tools provision resources across providers and which Kubernetes resources expose pods as network services.

150 questions33 easy74 medium43 hard

Focused practice

Practice Cloud Native Architecture questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Cloud Native Architecture

Be able to name the cloud native principles, pick the right Kubernetes resource to expose pods (Service), and identify infrastructure-as-code tooling that spans providers. For high availability, the key is designing across multiple regions with replication and failover, not relying on one cluster.

Core cloud native principles: microservices, containers, declarative APIs, immutable infrastructure, and loose coupling

Kubernetes Service objects for exposing pods as stable network endpoints, including ClusterIP and LoadBalancer types

Infrastructure as code tooling such as Terraform that provisions resources across multiple cloud providers

High availability patterns: multi-region Kubernetes clusters, replication, failover, and avoiding single points of failure

Why learners struggle

Why Cloud Native Architecture questions are commonly missed

NAT questions are missed when learners confuse the four address types (inside local, inside global, outside local, outside global) or misapply the interface direction. A translation rule can look correct but still fail if the ACL, interface, or direction is wrong.

  • ·Inside local vs inside global — inside local is the private source, inside global is the translated public address
  • ·PAT overloads — many sources share one public IP using unique port numbers
  • ·Interface direction — ip nat inside and ip nat outside must be on the correct interfaces
  • ·Static NAT vs dynamic NAT vs PAT — each serves a different use case
  • ·The NAT ACL identifies traffic to translate, not traffic to permit or deny
  • ·A missing translation can look like a routing problem if the interfaces are misconfigured

Watch out for

Common Cloud Native Architecture exam traps

  • ▸Confusing a Kubernetes Service with a Deployment or Ingress; the Service exposes pods as a network service, not the workload controller itself.
  • ▸Assuming a single cloud provider or region gives high availability; multi-region designs need replication and failover across clusters.
  • ▸Treating infrastructure as code as only configuration management; tools like Terraform provision and manage resources declaratively across providers.

Question index

All Cloud Native Architecture questions (150)

Click any question to see the full explanation, or start a practice session above.

1

A team wants to manage their Kubernetes infrastructure using code. Which tool is specifically designed for Infrastructure as Code (IaC) and can manage Kubernetes resources?

Medium
2

In the 12-factor app methodology, which factor describes the practice of storing configuration in environment variables?

Medium
3

In a service mesh architecture, which component is responsible for intercepting and managing traffic to and from a pod?

Medium
4

An SRE team is reviewing a stateless web tier that runs as a Deployment. They want the platform to automatically add replicas when average CPU utilization across the Pods rises above a target, and to remove replicas when load drops, without any manual intervention. Which Kubernetes resource should they configure?

Medium
5

In the context of the 12-factor app methodology, which factor is addressed by storing configuration in environment variables?

Hard
6

Which component in a service mesh architecture is responsible for handling inter-service communication on behalf of the application container?

Medium
7

In a service mesh architecture, what is the role of the sidecar proxy?

Medium
8

Which of the following best describes the purpose of the Cloud Native Computing Foundation (CNCF)?

Easy
9

In an event-driven architecture, what is the role of an event broker?

Medium
10

Which THREE of the following are benefits of using a service mesh? (Choose 3.)

Hard
11

Which component of the Istio service mesh is responsible for certificate signing and identity management?

Medium
12

Which component in a service mesh is responsible for handling traffic management, security, and observability as a sidecar proxy?

Medium
13

A team is designing a cloud-native application and wants to ensure that the failure of a single availability zone does not cause a full outage. They deploy the application across multiple zones and configure the orchestrator to distribute replicas evenly. Which cloud-native architecture principle does this scenario primarily demonstrate?

Medium
14

Which CNCF project is classified as a 'graduated' project?

Easy
15

Which THREE are typical characteristics of a cloud-native application?

Hard
16

You are implementing an API gateway pattern for a set of microservices. Which of the following is a typical responsibility of an API gateway?

Hard
17

A team is designing a cloud-native system that must maintain high availability across multiple cloud regions. The application uses Kubernetes clusters in each region. Which approach best ensures that the system can tolerate a full region failure while minimizing complexity?

Hard
18

In Istio, which component is responsible for enforcing traffic policies and collecting telemetry data at the pod level?

Hard
19

In a microservices application, you want to prevent cascading failures by limiting the number of concurrent requests to a downstream service. Which resilience pattern should you implement?

Hard
20

Match each Kubernetes object to its typical use case.

Medium
21

Which service mesh component is typically deployed as a sidecar proxy alongside application containers?

Easy
22

A company is adopting cloud-native architecture and wants to improve the resilience of its applications. Which TWO of the following are core principles of cloud-native architecture that directly contribute to resilience? (Choose two.)

Hard
23

What is the primary benefit of using an API gateway in a microservices architecture?

Medium
24

A company wants to adopt a GitOps workflow for managing their Kubernetes clusters. Which two tools are specifically designed for implementing GitOps on Kubernetes?

Medium
25

In a multi-cloud scenario, an organization wants to avoid vendor lock-in by abstracting infrastructure provisioning. Which tool is specifically designed to manage infrastructure as code across multiple cloud providers?

Medium
26

Which THREE of the following are components of the GitOps workflow? (Choose three.)

Hard
27

A team wants to deploy a multi-cloud application that uses cloud-specific services. Which pattern is most appropriate?

Hard
28

In the context of resiliency patterns, which pattern is designed to prevent a cascade of failures by isolating each component so that a failure in one component does not affect others?

Hard
29

An application is deployed across multiple cloud providers (AWS and GCP) to avoid vendor lock-in. This is an example of which pattern?

Hard
30

Which TWO of the following are features of a service mesh like Istio or Linkerd? (Select 2)

Hard
31

Which of the following patterns is used to improve resilience by isolating failures to a subset of components?

Hard
32

Which TWO of the following are characteristics of serverless computing?

Hard
33

A team is evaluating whether their application qualifies as cloud-native. They want to identify characteristics that are central to cloud-native architecture rather than incidental implementation details. Which TWO of the following are core characteristics of cloud-native architecture? (Choose two.)

Hard
34

In GitOps, what is the role of a tool like ArgoCD?

Medium
35

A cloud-native application is designed with multiple microservices that need to handle a sudden spike in traffic without manual intervention. Which Kubernetes feature best enables this?

Easy
36

An application requires external configuration that varies between environments (dev, staging, prod). Following the 12-factor app methodology, how should this configuration be provided?

Medium
37

Which THREE of the following are features provided by a service mesh like Istio? (Select THREE.)

Hard
38

Which TWO of the following are core principles of cloud native architecture according to the CNCF?

Medium
39

A team is deploying a microservices application on Kubernetes. They want to ensure that each microservice can be updated independently without affecting others, and that the application can tolerate the failure of a single microservice. Which cloud-native architecture principle are they applying?

Medium
40

A development team wants to implement a GitOps workflow for their Kubernetes deployments. Which tool is specifically designed for GitOps on Kubernetes?

Medium
41

What is the role of an API gateway in a microservices architecture?

Easy
42

A development team is containerizing a monolithic application into microservices. Which practice aligns with cloud-native architecture principles?

Easy
43

A team is designing a cloud-native application that requires each microservice to have its own database. This pattern is known as:

Medium
44

A team is designing a cloud-native system that must remain available even if an entire availability zone fails. They want to distribute workloads across multiple zones and automatically recover from failures. Which cloud-native architectural approach BEST addresses this requirement?

Hard
45

Which of the following best describes the purpose of the CNCF (Cloud Native Computing Foundation)?

Easy
46

A cloud-native application experiences intermittent failures when calling an external API. The team implements a pattern that allows the application to temporarily stop calling the failing API and serve stale data or a fallback response. Which resiliency pattern does this describe?

Hard
47

Which of the following is a core principle of cloud native architecture as defined by the CNCF?

Easy
48

Which GitOps tool is specifically designed for Kubernetes and follows the declarative GitOps pattern, continuously reconciling the desired state from a Git repository?

Easy
49

Which TWO of the following are key characteristics of cloud-native applications? (Select two.)

Medium
50

Which THREE are core principles of the Twelve-Factor App methodology?

Medium
51

What is the primary function of a service mesh like Istio?

Medium
52

An organization wants to adopt a cloud-native approach for its new application. Which characteristic is most important for the application to be considered cloud-native?

Easy
53

Which THREE of the following are benefits of using an event-driven architecture? (Choose three.)

Hard
54

Which of the following is a key principle of the 12-factor app methodology?

Medium
55

Which of the following is a benefit of using an API gateway pattern?

Hard
56

A cloud-native application uses a service mesh (Istio) for traffic management. The team notices increased latency in inter-service communication. Which likely cause should be investigated first?

Hard
57

A platform engineer is explaining cloud-native architecture to a new team. The team asks which statement BEST describes the relationship between microservices and cloud-native architecture. Which answer is correct?

Medium
58

What is the primary purpose of an API gateway in a microservices architecture?

Medium
59

Which TWO statements are true about cloud-native architecture?

Medium
60

Which TWO practices are recommended for designing cloud-native microservices? (Choose 2)

Hard
61

Which resource in Kubernetes is used to expose a set of pods as a network service?

Easy
62

In a serverless architecture using Knative, what happens when a function finishes processing an event and there are no pending events?

Hard
63

Which GitOps tools use a pull-based approach to synchronize the desired state in a Git repository with the actual state in a Kubernetes cluster? (Select all that apply.)

Medium
64

What is the purpose of the circuit breaker pattern in a microservices architecture?

Medium
65

A platform team is adopting cloud-native principles for a new microservices application. They want to ensure that each service can be independently deployed and scaled without affecting other services. Which design principle BEST supports this goal?

Medium
66

In serverless computing, what is the primary characteristic of Function-as-a-Service (FaaS)?

Medium
67

An organization wants to implement a serverless function that scales to zero when not in use. Which technology is specifically designed to achieve this on Kubernetes?

Medium
68

Which of the following best describes 'Infrastructure as Code' (IaC)?

Medium
69

A development team wants to adopt a cloud-native architecture for a new application. Which set of principles BEST describes the cloud-native approach?

Medium
70

Which command would you use to apply a manifest file 'deployment.yaml' to a Kubernetes cluster?

Medium
71

What is the primary purpose of the sidecar container in a service mesh?

Medium
72

A microservice logs errors when connecting to the database. The logs show 'connection refused'. Which troubleshooting step should be taken first?

Medium
73

An organization uses GitOps with ArgoCD to manage Kubernetes deployments. What is the PRIMARY advantage of this approach over traditional imperative deployment methods?

Medium
74

Which of the following is a core principle of the 12-factor app methodology?

Easy
75

Which CNCF project maturity level indicates that a project has adopted the CNCF Code of Conduct and is considered early-stage?

Easy
76

Which of the following is a key principle of the 12-factor app methodology related to managing configuration?

Hard
77

What is GitOps?

Easy
78

A platform engineer is explaining the role of the Kubernetes API server in a cloud-native architecture. Which statement BEST describes its primary function?

Easy
79

Which service mesh component is responsible for handling inter-service communication as a sidecar proxy?

Medium
80

Your organization runs a cloud-native e-commerce platform on Kubernetes. The platform consists of several microservices: a frontend service, an order service, a payment service, and a shipping service. All services communicate via HTTP REST APIs. Recently, during a flash sale event, the platform experienced a cascading failure. The order service became overwhelmed with requests and started responding slowly. This caused the frontend service to time out waiting for order responses, and eventually the frontend service crashed due to exhausted thread pools. The payment and shipping services were unaffected because they are called asynchronously via a message queue. You need to redesign the system to prevent such cascading failures in the future. Which approach is the most effective?

Hard
81

In a service mesh architecture, which component is responsible for intercepting and managing traffic between microservices?

Medium
82

In a multi-cloud architecture, what is a common use case for a service mesh?

Medium
83

Which THREE are key benefits of using a service mesh in a cloud-native architecture? (Choose 3)

Medium
84

A platform team runs a multi-tenant Kubernetes cluster for several product groups. They want each group's workloads to be logically isolated from one another, with separate quota limits and separate RBAC bindings, while still sharing the same cluster control plane and worker nodes. Which Kubernetes construct BEST provides this isolation boundary?

Easy
85

In an event-driven architecture using a message broker, which component is responsible for receiving events and forwarding them to subscribed services?

Medium
86

Which of the following is a benefit of using a service mesh?

Medium
87

According to the 12-factor app methodology, how should an application store configuration that varies between deployments (e.g., database connection strings)?

Medium
88

Which CNCF project is at the 'Graduated' maturity level and is widely used for container orchestration?

Medium
89

What is the purpose of a circuit breaker pattern in microservices?

Easy
90

Which TWO of the following are core principles of the 12-factor app? (Choose 2.)

Medium
91

In the context of the 12-factor app methodology, which factor emphasizes storing configuration in environment variables?

Easy
92

Which CNCF project maturity level indicates that a project has successfully adopted the CNCF governance and is considered stable for production use?

Easy
93

A development team is adopting a GitOps workflow for their Kubernetes applications. They want to ensure that the cluster state always matches the desired state defined in Git. Which component is responsible for continuously reconciling the cluster with the Git repository?

Medium
94

A platform team is designing a system that must continue serving requests for a product catalog even if the recommendation service becomes unavailable. The recommendation service calls the catalog service to fetch item details, and when it fails, the catalog service should keep responding to user traffic. Which cloud-native architecture principle BEST describes the required behavior for the catalog service?

Medium
95

Which THREE of the following are benefits of using a service mesh? (Select three.)

Hard
96

Which TWO of the following are core principles of the 12-factor app methodology? (Select TWO.)

Medium
97

What is the primary purpose of the CNCF (Cloud Native Computing Foundation)?

Easy
98

Which component in an event-driven architecture is responsible for decoupling event producers from consumers?

Medium
99

In a microservices architecture, which pattern is used to prevent cascading failures by limiting the number of concurrent requests to a service?

Medium
100

Which practice is a key principle of cloud-native architecture?

Easy
101

Which TWO of the following are essential components of a GitOps workflow? (Select two.)

Easy
102

An architecture review is comparing the sidecar proxy model used by service meshes against embedding resilience logic directly in each application's code. Which TWO statements accurately describe advantages of the sidecar proxy approach? (Choose two.)

Medium
103

In event-driven architecture, which pattern is commonly used to decouple producers and consumers, allowing asynchronous communication?

Hard
104

Which TWO tools are commonly used for GitOps? (Choose two.)

Medium
105

Which TWO are benefits of using a service mesh in cloud-native applications?

Hard
106

Drag and drop the steps to configure a Kubernetes Service of type LoadBalancer in a cloud environment into the correct order.

Medium
107

A startup is building a cloud-native application and wants to adopt a packaging format that bundles application code and its dependencies into a single immutable artifact that can run consistently across environments. Which technology BEST meets this requirement?

Easy
108

Which of the following is an example of Infrastructure as Code (IaC) tool?

Medium
109

A team is adopting cloud-native architecture and wants to ensure that a single failing component does not take down the entire application. They are reviewing the design of their microservices deployment. Which characteristic of cloud-native architecture is MOST directly related to limiting the impact of a component failure?

Easy
110

In the context of the 12-factor app methodology, which factor requires that an app's configuration be stored in environment variables?

Hard
111

You are a platform engineer at a fast-growing startup. The company runs a Kubernetes cluster with 50 worker nodes for its production microservices. Recently, the operations team has been struggling with manual configuration drift: developers SSH into nodes to install debugging tools, and some nodes have different kernel parameters or installed packages. This has caused intermittent outages when a pod is scheduled onto a non-standard node. The CTO wants a solution that ensures each node is identical, immutable, and reproducible. The cluster uses kubeadm for bootstrapping and runs on AWS EC2. Which approach best achieves the goal of immutable nodes?

Hard
112

Which Kubernetes resource is commonly used to implement the sidecar pattern for injecting a service mesh proxy?

Hard
113

In event-driven architecture, which component is responsible for decoupling event producers from consumers?

Hard
114

A company wants to manage its Kubernetes resources using Git as the single source of truth, with automated synchronization. Which approach should they use?

Medium
115

What is the primary purpose of a service mesh in a cloud-native architecture?

Medium
116

Which TWO of the following are examples of Infrastructure as Code (IaC) tools? (Choose two.)

Easy
117

Which THREE of the following are resiliency patterns commonly used in cloud native applications? (Choose three.)

Hard
118

Which CNCF project provides a graduated service mesh implementation that includes features like traffic management, security, and observability?

Easy
119

In a serverless architecture using Knative, what happens to a service that has not received traffic for an extended period?

Hard
120

Which THREE of the following are features typically provided by a service mesh? (Choose three.)

Hard
121

A team is implementing a multi-cloud strategy to avoid vendor lock-in. Which Kubernetes feature is most helpful for abstracting the underlying cloud provider?

Medium
122

A retail company runs its e-commerce platform on Kubernetes. During a flash sale, the application experiences high latency. The team notices that the database pods are CPU-bound and the application pods are waiting on database responses. Which architectural change would best address this bottleneck?

Medium
123

Which TWO of the following are examples of Infrastructure as Code (IaC) tools? (Choose 2.)

Easy
124

A team wants to deploy a serverless function that scales to zero when not in use. Which CNCF project is specifically designed for this purpose?

Medium
125

Which TWO of the following are principles of the 12-factor app? (Choose two.)

Medium
126

In event-driven architecture, what is the role of an event broker?

Hard
127

Which TWO of the following are benefits of using a service mesh? (Choose two.)

Medium
128

An organization wants to manage infrastructure using code to ensure consistent and repeatable deployments across multiple cloud providers. Which tool is MOST suitable for this multi-cloud Infrastructure as Code approach?

Medium
129

A startup is building a cloud-native application and wants to ensure that its services can be discovered and communicated with dynamically as they scale up and down. Which CNCF project provides a distributed key-value store that is commonly used for service discovery and configuration management in Kubernetes?

Easy
130

An engineering team runs a Kubernetes cluster and wants to ensure that a critical payment service continues to function during a partial network partition between two availability zones. The service currently depends on a single external authentication API in one zone. Which architectural change BEST supports the goal of maintaining payment processing during the partition?

Hard
131

A development team is designing a new microservices application to run on a Kubernetes cluster. They want to ensure that each microservice can be developed, deployed, and scaled independently. Which cloud native architecture principle are they primarily applying?

Easy
132

Which THREE are key characteristics of event-driven architecture? (Choose three.)

Hard
133

A team wants every microservice to ship its logs and metrics to a central backend, and they want to avoid running a separate agent container inside each application Pod. Which cloud native approach BEST fits this requirement while keeping collection decoupled from the application?

Medium
134

The exhibit shows a Deployment manifest for a frontend service. After deployment, the pods are running but the service reports that no endpoints are available. What is the most likely cause?

Medium
135

A company is evaluating cloud-native observability practices for its Kubernetes-based microservices. Which TWO practices are essential for achieving effective observability? (Choose two.)

Medium
136

Which component of an API gateway pattern is responsible for routing requests to the appropriate microservice based on the request path?

Medium
137

Which TWO of the following are principles of the 12-factor app methodology? (Choose two.)

Medium
138

Which of the following is a key difference between a service mesh and an API gateway?

Hard
139

Which of the following best describes the GitOps pattern?

Hard
140

Which TWO of the following are benefits of using a multi-cloud strategy? (Select TWO.)

Easy
141

Which tool is used to manage infrastructure as code and can provision resources across multiple cloud providers?

Easy
142

A company is adopting a multi-cloud strategy to avoid vendor lock-in. Which pattern BEST supports deploying applications across different cloud providers with minimal changes?

Medium
143

A team wants to deploy a workload that must run on every node in a Kubernetes cluster, including new nodes added later. Which resource type should they use?

Hard
144

A team is building a serverless application using Knative. They want the application to scale to zero when idle. Which Knative resource type should they use?

Hard
145

Which of the following is a primary goal of the Cloud Native Computing Foundation (CNCF)?

Easy
146

Which TWO of the following are core principles of cloud native architecture? (Choose two.)

Medium
147

Which component in a service mesh is responsible for collecting telemetry data and enforcing traffic policies?

Medium
148

Which of the following best describes the 12-factor app methodology's approach to configuration?

Medium
149

Which THREE of the following are benefits of using a service mesh in a cloud native architecture?

Easy
150

Which TWO of the following are common characteristics of serverless computing? (Choose two.)

Medium

Frequently asked questions

What does the Cloud Native Architecture domain cover on the KCNA exam?
Be able to name the cloud native principles, pick the right Kubernetes resource to expose pods (Service), and identify infrastructure-as-code tooling that spans providers. For high availability, the key is designing across multiple regions with replication and failover, not relying on one cluster.
How many questions are in this domain?
This page lists all 150 Cloud Native Architecture questions in the KCNA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Cloud Native Architecture questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
cncf-kcna CNCF-KCNA kcna cloud native arch Practice Questions