KCNA Kubernetes Fundamentals Practice Question
Which THREE statements about Labels and Selectors are correct?
⚠ Common exam trap
CNCF often tests the distinction between labels and annotations, trapping candidates who assume annotations can also be used for selection, when in fact only labels support selector-based filtering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Services use selectors to determine which Pods receive traffic
Option A is correct because a Service's spec.selector matches Pod labels, and the kube-proxy/EndpointSlice machinery routes traffic only to Pods whose labels satisfy that selector. Option B is correct because a Deployment (and ReplicaSet) uses spec.selector.matchLabels/matchExpressions to determine which Pods it owns and manages, ensuring it only adopts Pods matching those labels. Option C is correct because labels are arbitrary key/value metadata designed for organizing objects and for grouping/selecting subsets via label selectors (equality- and set-based). Option D is incorrect because label keys must be unique per object, but labels are not required to be unique across a namespace—many objects can share the same labels. Option E is incorrect because annotations are non-identifying metadata and cannot be used with selectors for selection; only labels are queryable by selectors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Services use selectors to determine which Pods receive traffic
Why this is correct
Services match Pods through label selectors, continuously evaluating which Pods satisfy the specified key-value criteria. This satisfies the stem's requirement by describing how traffic routing is decoupled from Pod identity: any Pod bearing matching labels joins the Service's endpoint list, regardless of name, IP address or node placement.
- ✓
Selectors are used by Deployments to identify the Pods they manage
Why this is correct
Deployments use label selectors to define which Pods fall under their management, matching Pod labels to the selector specified in the Deployment's spec. This satisfies the stem's requirement that selectors identify managed Pods, enabling ReplicaSets to maintain the correct replica count and perform rolling updates on exactly those Pods.
- ✓
Labels can be used to organize and select subsets of objects
Why this is correct
Labels are key-value pairs attached to Kubernetes objects, letting you group and query subsets across namespaces via selectors. This satisfies the stem's requirement that labels organise and select subsets of objects, since selectors filter by label rather than by name or UID.
- ✗
Labels must be unique within a namespace
Why it's wrong here
Label keys must be unique per object, but the same label value may repeat across many objects; uniqueness is not namespace-scoped. Namespace-scoped uniqueness applies to resource names, so this would be correct when naming objects such as Pods or Services within a namespace.
- ✗
Annotations are used for identification and selection
Why it's wrong here
Annotations hold non-identifying metadata and cannot be used by selectors; only labels are queried by label selectors. Annotations suit tooling metadata like build IDs or contact details, so they would be the correct choice when storing descriptive information that must not affect object selection.
Go deeper
Related to this question
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on KCNA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE of the following are true about Kubernetes labels and selectors?
hard- A.Labels are encrypted at rest by default
- ✓ B.Set-based selectors support operators like 'In' and 'NotIn'
- ✓ C.Selectors can be used by Services to identify which pods to route traffic to
- D.Labels are immutable after creation
- ✓ E.Labels can be used to organize and select subsets of objects
Why B: Option B is correct because set-based selectors support operators such as In, NotIn, Exists, and DoesNotExist, allowing matching against a set of values rather than a single equality. Option C is correct because a Service uses its selector to match pod labels and route traffic only to the pods whose labels satisfy that selector. Option E is correct because labels are key/value pairs attached to objects specifically so users can organize and select subsets of objects, for example with kubectl get pods -l app=web. Option A is not correct because labels are ordinary metadata and are not encrypted at rest by default; encryption at rest applies to etcd data only if configured. Option D is not correct because labels are mutable and can be added, updated, or removed after object creation.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.