Courseiva
Container Orchestration →easyMultiple Choice

KCNA Container Orchestration Practice Question

What is the purpose of the Container Runtime Interface (CRI)?

⚠ Common exam trap

Watch out — candidates often confuse the CRI with the CNI or OCI, assuming the CRI manages networking or image standards, when in fact it strictly defines the runtime API for container lifecycle operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To allow kubelet to communicate with different container runtimes

The Container Runtime Interface (CRI) is a plugin interface that enables the kubelet to use a variety of container runtimes without needing to recompile the Kubernetes components. It defines the API for creating, starting, stopping, and deleting containers, allowing the kubelet to communicate with runtimes like containerd, CRI-O, or Docker (via dockershim, now deprecated). Option D is correct because the CRI's primary purpose is to abstract the runtime implementation from the kubelet, enabling interoperability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To manage container networking

    Why it's wrong here

    Container networking is delegated to CNI plugins, which configure pod interfaces and IP addresses; CRI only handles runtime lifecycle calls. It is tempting because CRI and CNI are both kubelet-facing plugin interfaces, but the axis of difference is runtime execution versus network attachment.

  • ✗

    To define a standard for container images

    Why it's wrong here

    CRI standardises the kubelet-to-runtime gRPC API for lifecycle operations; image format is governed by the Open Container Initiative specification. It is tempting because CRI plugins do pull and manage images, but defining image structure is OCI's remit, not CRI's.

  • ✗

    To orchestrate multi-container pods

    Why it's wrong here

    CRI is an abstraction layer letting kubelet talk to differing container runtimes; pod orchestration is the scheduler's and controller manager's job. It is tempting because CRI sits inside the kubelet, which does manage pod sandboxes, but multi-container orchestration across nodes is handled elsewhere.

  • ✓

    To allow kubelet to communicate with different container runtimes

    Why this is correct

    CRI is the abstraction layer defining gRPC interfaces that let kubelet manage containers without embedding runtime-specific code, so containerd, CRI-O and others plug in interchangeably. This satisfies the stem's requirement for kubelet communicating with different container runtimes.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.