KCNA Cloud Native Application Delivery Practice Question
Which THREE are common features of progressive delivery?
⚠ Common exam trap
KCNA often tests whether candidates confuse progressive delivery with plain rolling updates — the trap is picking 'all-at-once' or 'manual verification' as features when both contradict the gradual, automated nature of progressive delivery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Feature flags to enable/disable features
Progressive delivery is an extension of continuous delivery that reduces release risk by exposing changes to a subset of users before full rollout, and feature flags (A) are a core mechanism because they decouple deployment from release, letting you enable or disable functionality for specific users, cohorts, or percentages without redeploying. Gradual traffic shifting (B) is also fundamental, as it incrementally routes a growing percentage of traffic to the new version (e.g., canary or blue/green with weighted routing) so impact can be observed at small blast radius. Automated analysis and rollback (C) is the third key feature, since progressive delivery relies on metrics/health signals (e.g., error rates, latency) to automatically promote or revert the release when thresholds are breached. By contrast, all-at-once deployment (D) is the opposite of progressive delivery because it exposes every user simultaneously with no staged risk control, and manual verification for every change (E) contradicts the automation and continuous, data-driven promotion that progressive delivery depends on.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Feature flags to enable/disable features
Why this is correct
Feature flags decouple deployment from release, letting operators enable or disable functionality at runtime for specific users or cohorts. This satisfies progressive delivery's requirement to expose changes to a subset first, so impact can be observed before full rollout.
- ✓
Gradual traffic shifting
Why this is correct
Gradual traffic shifting routes a growing percentage of requests to the new version, typically via a service mesh or ingress controller. This satisfies progressive delivery's constraint of limiting blast radius, since exposure increases only as metrics remain healthy.
- ✓
Automated analysis and rollback
Why this is correct
Automated analysis evaluates metrics such as error rate and latency against thresholds during rollout, triggering rollback without human intervention. This satisfies progressive delivery's requirement to halt and revert a bad release automatically, containing impact before it reaches the whole user base.
- ✗
All-at-once deployment
Why it's wrong here
Progressive delivery releases gradually to a subset of users, using canaries, blue-green or feature flags, so all-at-once deployment defeats the controlled exposure it provides. It is tempting because all-at-once is the default for basic deployments, and for a low-risk internal service where instant rollout is acceptable it would be correct.
- ✗
Manual verification for every change
Why it's wrong here
Progressive delivery automates verification through metrics, analysis templates and automated rollback; manual approval for every change contradicts that automation. It is tempting because approval gates appear in some pipelines, and in a regulated release process requiring human sign-off before promotion, manual verification would be correct.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.