KCNA Cloud Native Application Delivery Practice Question
What is the primary purpose of a container registry in the CI/CD pipeline?
⚠ Common exam trap
KCNA often tests the distinction between the roles of different CI/CD components, and a common trap is confusing the registry with tools that perform scanning or testing, leading candidates to select an answer that describes a secondary or integrated feature rather than the primary purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To store and distribute container images
A container registry is a centralized repository for storing and distributing container images, such as Docker images. In a CI/CD pipeline, after an image is built, it is pushed to a registry (e.g., Docker Hub, Harbor, or a cloud provider's registry) so that it can be pulled and deployed to various environments. This enables versioning, sharing, and consistent deployment of containerized applications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
To store and distribute container images
Why this is correct
A container registry stores versioned container images and serves them to nodes during deployment, which is precisely the distribution role the CI/CD pipeline requires. Build stages push tagged images; runtime environments pull them by digest or tag, satisfying the stem's demand for a dedicated artefact repository rather than a build or orchestration function.
- ✗
To run unit tests on container images
Why it's wrong here
Registries only store and serve images; they execute nothing. Unit tests run in the CI runner or build stage before the image is pushed. It is tempting because registries can trigger webhooks or scanning on push, which looks like pipeline activity, but no test execution occurs inside the registry.
- ✗
To store application source code
Why it's wrong here
A container registry stores and distributes built OCI images by tag and digest; source code belongs in a version control system such as Git. The confusion arises because registries are often reachable from the same CI/CD tooling and pipelines push images after committing code, but the registry never holds the repository itself.
- ✗
To scan images for vulnerabilities
Why it's wrong here
Registries store and distribute images; vulnerability scanning is a separate capability, often provided by the registry's optional scanning feature or a dedicated tool, and is not its primary purpose. It is tempting because integrated scanners run on push, but the registry's core function remains image storage and retrieval.
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.