KCNA Container Orchestration Practice Question
Which of the following is a container runtime that implements the Container Runtime Interface (CRI)?
⚠ Common exam trap
CNCF often tests the misconception that Docker is a CRI-compliant runtime, when in fact Docker uses a separate adapter (dockershim) that was removed in Kubernetes v1.24, making containerd the standard CRI implementation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
containerd
containerd is a high-level container runtime that directly implements the Container Runtime Interface (CRI) by exposing a gRPC API that kubelet can call to manage pods and containers. It was originally extracted from Docker and is now the default runtime in many Kubernetes distributions, providing image transfer, container lifecycle management, and storage/network attachment without requiring Docker as an intermediary.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
containerd
Why this is correct
Containerd implements the Kubernetes Container Runtime Interface, satisfying the stem's requirement for a CRI-compliant runtime. It manages the full container lifecycle — image transfer, storage, and execution — via a daemon, and is the default runtime for most Kubernetes distributions, unlike Docker, which required the deprecated dockershim adapter.
- ✗
Docker
Why it's wrong here
Docker predates and does not natively implement the Container Runtime Interface; Kubernetes talks to it through the deprecated dockershim, which was removed in v1.24. It is tempting because Docker is the best-known container tool, and would be correct when asking for a full container engine offering image building and developer tooling.
- ✗
runc
Why it's wrong here
runc is a low-level OCI runtime that creates and runs containers from a bundle, but it does not implement the CRI gRPC service; CRI is implemented by higher-level runtimes such as containerd or CRI-O, which invoke runc. It is tempting because runc underpins most Kubernetes nodes, yet it would be the right answer only when asked for an OCI runtime.
- ✗
kubelet
Why it's wrong here
Kubelet is the node agent that consumes the CRI to launch pods via a runtime such as containerd; it does not implement the CRI itself. It is tempting because kubelet sits closest to container execution, but the interface is implemented by the runtime shim, not the caller.
Go deeper
Related to this question
Learn chapter
Pods and Workload Management
Key term
ReplicaSet and Replication
A ReplicaSet ensures a specified number of identical pod instances are running at all times in Kubernetes, using replication to maintain availability and stability.
Key term
Pods and Containers
Pods are the smallest deployable units in Kubernetes that wrap one or more containers, sharing network and storage resources.
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.