Courseiva

KCNA · topic practice

Container Orchestration practice questions

Container Orchestration is the largest KCNA domain, covering how Kubernetes schedules, runs, and connects workloads. Questions test core API objects — Pods, Deployments, Jobs, Services, NetworkPolicies — plus probes, container spec fields, and the reconciliation model, using scenario-style multiple choice rather than hands-on kubectl tasks.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Container Orchestration

What the exam tests

What to know about Container Orchestration

Be able to pick the right workload controller and probe for a scenario, and name required container fields. The most important thing: know that liveness restarts containers while readiness controls Service traffic, and that NetworkPolicies are deny-by-default only once a policy selects the pod.

Pod and container spec fields, including required name and image keys

Liveness versus readiness probes and their effect on restarts and endpoints

NetworkPolicy objects selecting pods to allow or deny traffic

Job versus Deployment versus CronJob selection for run-to-completion workloads

Watch out for

Common Container Orchestration exam traps

  • ▸Confusing liveness and readiness: liveness failures restart the container, readiness failures only remove the Pod from Service endpoints.
  • ▸Assuming NetworkPolicies apply by default; without a policy, all pod traffic is allowed, and enforcement needs a CNI plugin that supports them.
  • ▸Choosing a Deployment for batch work; Jobs, not Deployments, track successful completions and retries.

Practice set

Container Orchestration questions

20 questions · select your answer, then reveal the explanation

An application running in a Kubernetes pod needs to access a database that is deployed on a VM outside the cluster. The database IP is stable. Which is the best way to expose the database to the pod?

A team notices that a ReplicaSet is not creating the desired number of pods. The ReplicaSet YAML is correctly configured with replicas: 3. The cluster has sufficient resources. What is the most likely cause?

Which TWO of the following are valid ways to expose a set of pods as a network service in Kubernetes?

Which TWO of the following are valid methods to expose a set of pods to external traffic in Kubernetes?

Your organization runs a microservices application in a Kubernetes cluster with 5 worker nodes. Each microservice is deployed as a Deployment with 3 replicas. Recently, users report intermittent timeouts when accessing the frontend service. The frontend communicates with a backend service via ClusterIP. You check the backend pods and find that one of the three replicas is in CrashLoopBackOff. The other two backend pods are healthy. The frontend deployment has no readiness or liveness probes. You notice that the frontend's connection pool to the backend has a timeout of 5 seconds. The crashing backend pod logs show an occasional NullPointerException that causes the container to restart, but the pod becomes ready after restart within 2 seconds. However, the frontend's connection pool does not evict unhealthy connections quickly. What is the best course of action to reduce timeouts?

Drag and drop the steps to update a Kubernetes Secret and ensure Pods use the new value into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Match each Kubernetes component to its role in the control plane.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Exposes the Kubernetes API and acts as the front-end

Runs controller processes like Node and Replication controllers

Assigns pods to nodes based on resource availability

Consistent and highly-available key-value store for all cluster data

Interacts with underlying cloud provider's APIs

A pod in the 'production' namespace is in a CrashLoopBackOff state. The pod has been running successfully for several days. You run 'kubectl describe pod app-pod -n production' and see the message: 'OOMKilled'. What is the MOST appropriate action to resolve this issue?

A developer creates a Deployment with replicas: 3 and strategy type: RollingUpdate with maxSurge: 1 and maxUnavailable: 1. During a rolling update, the Deployment controller creates a new ReplicaSet. After the new ReplicaSet has 2 pods ready, the node running one of the original ReplicaSet's pods fails. What is the MOST likely number of total pods running after the node failure, assuming no other actions?

You have a microservices application where Service A needs to communicate with Service B running in a different namespace ('backend'). Both namespaces have a NetworkPolicy that denies all ingress by default. You create a NetworkPolicy in the 'backend' namespace allowing ingress from pods with label 'app: frontend'. What else is needed for Service A to reach Service B?

A user wants to ensure that a pod is automatically restarted if its main process crashes. Which Kubernetes controller should they use?

Which command would you use to view the logs of a specific container in a multi-container pod, using the short flag?

What is the role of etcd in a Kubernetes cluster?

An administrator wants to ensure that a Deployment named 'webapp' always has exactly 3 replicas running across distinct nodes to improve fault tolerance. Which field in the Deployment spec should they configure?

A Deployment manages 3 replicas of a pod. During a rolling update, one of the new pods enters CrashLoopBackOff. What happens next?

A pod in the 'production' namespace is in a CrashLoopBackOff state. The pod has been running successfully for several days. You run 'kubectl describe pod app-pod -n production' and see the message: 'OOMKilled'. What is the MOST appropriate action to resolve this issue?

An administrator wants to ensure that a specific pod only runs on nodes that have solid-state drives (SSDs). Nodes with SSDs are labeled with 'disktype=ssd'. Which pod specification field should be used?

A Kubernetes cluster has a Service named 'my-svc' in the 'default' namespace. Which command would correctly expose this service as an external endpoint using a cloud load balancer?

What is the purpose of a readiness probe in a Kubernetes pod?

Which TWO of the following are characteristics of immutable infrastructure? (Select two.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Container Orchestration sessions

Start a Container Orchestration only practice session

Every question in these sessions is drawn from the Container Orchestration domain — nothing else.

Related practice questions

Related KCNA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the KCNA exam test about Container Orchestration?
Be able to pick the right workload controller and probe for a scenario, and name required container fields. The most important thing: know that liveness restarts containers while readiness controls Service traffic, and that NetworkPolicies are deny-by-default only once a policy selects the pod.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Container Orchestration questions in a focused session?
Yes — the session launcher on this page draws every question from the Container Orchestration domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other KCNA topics?
Use the topic links above to move to related areas, or go back to the KCNA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the KCNA exam covers. They are not copied from any real exam or dump site.