Courseiva
Container Orchestration →mediumMultiple Choice

KCNA Container Orchestration Practice Question

What is the concept of 'immutable infrastructure' as applied to Kubernetes?

⚠ Common exam trap

CNCF often tests the distinction between 'immutable' (replace) and 'mutable' (update in place), and the trap here is that candidates confuse the concept with build-time practices (like using the same base image) or configuration injection methods, rather than the core runtime behavior of replacing Pods.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Pods are replaced with new versions rather than being modified

Immutable infrastructure in Kubernetes means that instead of modifying running Pods or their containers (e.g., patching a binary or updating a config file in place), you replace the entire Pod with a new version. This is enforced by Kubernetes' declarative model: when you update a Deployment's Pod template, the controller creates new Pods with the new image and terminates the old ones. This ensures consistency, repeatability, and eliminates configuration drift, as every change results in a fresh, identical instance from the same image.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configuration is stored in environment variables only

    Why it's wrong here

    Environment variables are one configuration injection mechanism, not immutability; they can be changed on a running pod without redeploying it. It is tempting because twelve-factor configuration externalises settings, and that approach is correct when the requirement is separating config from code across environments.

  • ✗

    Containers are rebuilt from the same base image every time

    Why it's wrong here

    Rebuilding from the same base image still permits mutable runtime layers and configuration drift; immutability concerns never modifying deployed instances, not image provenance. It is tempting because identical base images underpin reproducible builds, and that practice is correct when the goal is consistent container provenance rather than immutable deployment.

  • ✗

    Infrastructure components are never replaced; they are updated in place

    Why it's wrong here

    Immutable infrastructure replaces components wholesale rather than mutating running instances; in-place updates leave drift and untracked state, defeating reproducibility. It is tempting because patching live nodes is the traditional operational habit, and in-place upgrade is legitimate for stateful systems where replacement would lose data.

  • ✓

    Pods are replaced with new versions rather than being modified

    Why this is correct

    Immutable infrastructure means running instances are never patched or reconfigured in place; instead, Pods are destroyed and recreated from an updated image or manifest. This satisfies the scenario's requirement by eliminating configuration drift, since every replacement Pod starts from an identical, version-controlled definition rather than accumulating manual changes.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.