KCNA Container Orchestration Practice Question
What is the Container Runtime Interface (CRI)?
⚠ Common exam trap
Candidates often confuse the CRI with container image specifications (OCI Image Spec) or container runtime tools (like Docker), but the CRI is strictly an API interface between the kubelet and the runtime, not a tool or a specification for images.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An API between kubelet and container runtime
The Container Runtime Interface (CRI) is a plugin interface that enables the kubelet to use a variety of container runtimes without needing to recompile the kubelet. It defines a gRPC API (protocol buffers) for the kubelet to communicate with the container runtime, covering operations like pod lifecycle management and image management. Option D correctly identifies this as the API between the kubelet and the container runtime.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A tool for building container images
Why it's wrong here
CRI is a plugin interface letting kubelet talk to container runtimes such as containerd or CRI-O; it does not build images. It is tempting because container tooling clusters together, but image building belongs to tools like Buildah or Docker, not the runtime interface.
- ✗
A standard for container runtime logs
Why it's wrong here
CRI defines the gRPC contract between kubelet and container runtimes for pod and container lifecycle operations, not a logging format. It is tempting because runtimes do emit logs, but log handling is a separate concern; CRI's actual scope is runtime abstraction, not log standardisation.
- ✗
A specification for container images
Why it's wrong here
CRI governs runtime operations such as creating, starting, and stopping containers; it does not specify image formats. It is tempting because images and runtimes are closely related in Kubernetes, but image specification falls under the Open Container Initiative, while CRI abstracts the runtime itself.
- ✓
An API between kubelet and container runtime
Why this is correct
CRI is the abstraction layer kubelet calls to start, stop and inspect containers, decoupling Kubernetes from any specific runtime. It satisfies the stem's requirement by defining the gRPC API between kubelet and runtimes such as containerd or CRI-O, so runtimes can be swapped without recompiling kubelet.
Go deeper
Related to this question
Learn chapter
Container Orchestration Essentials
Key term
Container Runtime Interface
The Container Runtime Interface (CRI) is a standardized plugin protocol that allows Kubernetes to work with different container runtimes without needing to change its core code.
Key term
Pod Lifecycle
The Pod Lifecycle describes the sequence of states a Kubernetes pod passes through from creation to termination, including pending, running, succeeded, failed, and unknown conditions.
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.