KCNA Cloud Native Architecture Practice Question
In a multi-cloud scenario, an organization wants to avoid vendor lock-in by abstracting infrastructure provisioning. Which tool is specifically designed to manage infrastructure as code across multiple cloud providers?
⚠ Common exam trap
KCNA often tests the boundary between Kubernetes-ecosystem tools (Helm, Istio, ArgoCD) and general infrastructure-as-code tools (Terraform) — candidates pick Helm because it 'manages infrastructure' in a loose sense, missing that it only manages Kubernetes manifests.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Terraform
Terraform is a declarative infrastructure-as-code tool that uses provider plugins to manage resources across AWS, Azure, GCP, and many other platforms from a single configuration language (HCL). Its provider model and state file make it the canonical choice for multi-cloud, vendor-neutral infrastructure provisioning. This directly addresses the requirement to avoid vendor lock-in by abstracting provisioning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Helm
Why it's wrong here
Helm packages and templates Kubernetes manifests into charts; it deploys workloads into a cluster rather than provisioning cloud infrastructure across providers. It is tempting because charts are declarative and reusable, but they target the Kubernetes API, not provider resource APIs, so vendor lock-in at the infrastructure layer remains.
- ✗
Istio
Why it's wrong here
Istio is a service mesh handling traffic routing, mTLS and observability between workloads; it provisions no cloud infrastructure and abstracts no provider APIs. It is tempting because it spans clusters, but that span is network policy, not resource provisioning, so it cannot deliver the multi-cloud IaC abstraction required.
- ✓
Terraform
Why this is correct
Terraform uses provider plugins to translate a single HCL configuration into each cloud's native API calls, managing state across AWS, Azure and GCP. This provider abstraction lets the organisation provision identical infrastructure on multiple clouds, directly avoiding vendor lock-in.
- ✗
ArgoCD
Why it's wrong here
ArgoCD is a GitOps continuous delivery controller that synchronises Kubernetes manifests into clusters; it does not provision cloud infrastructure across providers. It is tempting because it manages declarative desired state, but that state covers workloads, not multi-cloud resources, which Terraform handles via provider plugins.
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.