KCNA Cloud Native Application Delivery Practice Question
Which TWO of the following are benefits of implementing progressive delivery techniques (e.g., canary releases)?
⚠ Common exam trap
KCNA often tests the misconception that progressive delivery eliminates the need for monitoring or CI/CD, when in fact it depends heavily on both.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Allows testing new features with a subset of users
Option B is correct because progressive delivery techniques such as canary releases deliberately expose a new version to a small subset of users (often a percentage of traffic) so that real-world behavior and feedback can be gathered before a full rollout. Option E is correct because by limiting the initial blast radius to that subset, a faulty release can be detected and rolled back before it reaches the entire user base, thereby reducing the risk of deploying a bad version to all users. Option A is incorrect because progressive delivery complements, rather than replaces, a CI/CD pipeline — the pipeline still builds, tests, and deploys the artifacts that progressive delivery then releases gradually. Option C is incorrect because progressive delivery depends heavily on monitoring and alerting to detect regressions and trigger rollbacks. Option D is incorrect because progressive delivery reduces risk but does not guarantee zero downtime, which depends on architecture and deployment mechanics.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Replaces the need for a CI/CD pipeline
Why it's wrong here
Canary releases sit on top of a CI/CD pipeline, consuming its build and deploy stages rather than removing them; they add traffic-splitting and analysis. It tempts because progressive delivery automates promotion decisions, which can feel like it subsumes pipeline duties, yet pipelines remain mandatory to produce artefacts.
- ✓
Allows testing new features with a subset of users
Why this is correct
Canary releases route a small percentage of live traffic to the new version, so real users exercise the feature before full rollout. This directly satisfies the stem's requirement to test with a subset, limiting blast radius and enabling fast rollback if metrics degrade.
- ✗
Eliminates the need for monitoring and alerting
Why it's wrong here
Progressive delivery depends on monitoring and alerting to evaluate canary metrics and trigger rollback; removing them defeats the technique. It tempts because automated analysis replaces manual release gates, which can look like observability is no longer needed, when in fact it becomes the decision input.
- ✗
Guarantees zero downtime
Why it's wrong here
Canary releases shift traffic gradually and can roll back, but they cannot guarantee zero downtime — a bad canary still serves some users, and rollback takes time. It tempts because gradual rollout reduces blast radius, which is often mistaken for eliminating outages entirely.
- ✓
Reduces the risk of deploying a bad version to all users
Why this is correct
Canary releases route a small slice of live traffic to the new version first, so a defective build affects only that subset rather than the whole user base. This directly satisfies the stem's risk-reduction benefit: faults surface under real conditions while the majority still runs the stable release, enabling rollback before full exposure.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.