KCNA Container Orchestration Practice Question
What is the purpose of the Container Runtime Interface (CRI) in Kubernetes?
⚠ Common exam trap
A common exam trap is confusing the CRI's role in runtime abstraction with storage (CSI) or networking (CNI) interfaces, leading candidates to select options B or C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To allow kubelet to use different container runtimes
The Container Runtime Interface (CRI) is a plugin interface that enables the kubelet to use a variety of container runtimes without needing to recompile the Kubernetes source code. By defining a standard API (gRPC-based) for runtime operations like pulling images and managing containers, CRI decouples Kubernetes from specific runtime implementations such as containerd, CRI-O, or Docker (via dockershim). This abstraction allows cluster administrators to choose the most suitable runtime for their environment while maintaining compatibility with the Kubernetes control plane.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
To allow kubelet to use different container runtimes
Why this is correct
CRI is the abstraction layer between kubelet and container runtimes, defining gRPC endpoints for image and container lifecycle operations. It lets kubelet drive containerd, CRI-O or other compliant runtimes interchangeably, decoupling Kubernetes releases from any single runtime implementation.
- ✗
To manage persistent storage for containers
Why it's wrong here
CRI abstracts container runtime operations for the kubelet, covering image pulling and container lifecycle; persistent storage is handled by CSI drivers. It would be correct when integrating storage volumes, not runtimes. The two interfaces address separate concerns despite both being plugin APIs.
- ✗
To provide a network plugin interface for pods
Why it's wrong here
CRI standardises how the kubelet invokes container runtimes such as containerd or CRI-O; pod networking is handled by CNI plugins instead. It would be the right interface when selecting or swapping network plugins, not runtimes. Confusing the two is the trap.
- ✗
To define a standard for container images
Why it's wrong here
CRI defines the gRPC interface between kubelet and container runtimes, not an image format; image packaging is governed by the OCI image specification. It would be correct when implementing a runtime shim, not when standardising images. The stem asks about runtime abstraction.
Go deeper
Related to this question
Learn chapter
Container Orchestration Essentials
Key term
Container Runtime Interface
The Container Runtime Interface (CRI) is a standardized plugin protocol that allows Kubernetes to work with different container runtimes without needing to change its core code.
Key term
ReplicaSet and Replication
A ReplicaSet ensures a specified number of identical pod instances are running at all times in Kubernetes, using replication to maintain availability and stability.
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.