KCNA Container Orchestration Practice Question
What is the purpose of the Container Runtime Interface (CRI)?
⚠ Common exam trap
Watch out — candidates often confuse the CRI with the CNI or OCI, assuming the CRI manages networking or image standards, when in fact it strictly defines the runtime API for container lifecycle operations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To allow kubelet to communicate with different container runtimes
The Container Runtime Interface (CRI) is a plugin interface that enables the kubelet to use a variety of container runtimes without needing to recompile the Kubernetes components. It defines the API for creating, starting, stopping, and deleting containers, allowing the kubelet to communicate with runtimes like containerd, CRI-O, or Docker (via dockershim, now deprecated). Option D is correct because the CRI's primary purpose is to abstract the runtime implementation from the kubelet, enabling interoperability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To manage container networking
Why it's wrong here
Container networking is delegated to CNI plugins, which configure pod interfaces and IP addresses; CRI only handles runtime lifecycle calls. It is tempting because CRI and CNI are both kubelet-facing plugin interfaces, but the axis of difference is runtime execution versus network attachment.
- ✗
To define a standard for container images
Why it's wrong here
CRI standardises the kubelet-to-runtime gRPC API for lifecycle operations; image format is governed by the Open Container Initiative specification. It is tempting because CRI plugins do pull and manage images, but defining image structure is OCI's remit, not CRI's.
- ✗
To orchestrate multi-container pods
Why it's wrong here
CRI is an abstraction layer letting kubelet talk to differing container runtimes; pod orchestration is the scheduler's and controller manager's job. It is tempting because CRI sits inside the kubelet, which does manage pod sandboxes, but multi-container orchestration across nodes is handled elsewhere.
- ✓
To allow kubelet to communicate with different container runtimes
Why this is correct
CRI is the abstraction layer defining gRPC interfaces that let kubelet manage containers without embedding runtime-specific code, so containerd, CRI-O and others plug in interchangeably. This satisfies the stem's requirement for kubelet communicating with different container runtimes.
Go deeper
Related to this question
Learn chapter
Container Orchestration Essentials
Key term
ReplicaSet and Replication
A ReplicaSet ensures a specified number of identical pod instances are running at all times in Kubernetes, using replication to maintain availability and stability.
Key term
Container Runtime Interface
The Container Runtime Interface (CRI) is a standardized plugin protocol that allows Kubernetes to work with different container runtimes without needing to change its core code.
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.