Courseiva

KCNA Cloud Native Application Delivery Practice Question

Which TWO of the following are capabilities of ArgoCD? (Choose two.)

⚠ Common exam trap

The trap is conflating CI and CD responsibilities — candidates assume ArgoCD builds images or runs tests because it is part of a deployment pipeline, but ArgoCD is strictly a GitOps CD tool.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automated application sync from Git to cluster

ArgoCD is a declarative GitOps continuous delivery tool for Kubernetes, and option B is correct because it continuously monitors Git repositories and automatically syncs the desired application state defined in Git to the target cluster. Option C is also correct because ArgoCD detects configuration drift between the live cluster state and the desired state in Git and can self-heal by reapplying the Git-defined manifests to restore the correct configuration. Option A is incorrect because ArgoCD does not build container images; that is the job of CI tools such as Jenkins, GitLab CI, or Tekton. Option D is incorrect because running unit tests is a CI activity, not a core ArgoCD capability. Option E is incorrect because ArgoCD does not manage secrets via Kubernetes Secrets as a built-in capability; secret management is typically handled by external tools like Sealed Secrets, SOPS, or Vault.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Building container images from source code

    Why it's wrong here

    ArgoCD is a GitOps continuous-delivery controller that synchronises cluster state with Git manifests; it does not compile source code into images. It is tempting because image building sits adjacent in CI pipelines, but that task belongs to tools such as Kaniko or Buildah.

  • ✓

    Automated application sync from Git to cluster

    Why this is correct

    ArgoCD continuously reconciles cluster state against Git, automatically applying declared manifests when drift is detected. This satisfies the stem's requirement for automated sync from Git to cluster, the pull-based GitOps mechanism ArgoCD implements natively without external CI triggers.

  • ✓

    Self-healing to correct configuration drift

    Why this is correct

    ArgoCD continuously reconciles live cluster state against the desired manifests stored in Git, automatically reverting out-of-band changes without human intervention. This satisfies the GitOps drift-correction requirement, since any manual edit diverging from the declared source of truth is detected and overwritten to restore the intended configuration.

  • ✗

    Running unit tests during deployment

    Why it's wrong here

    ArgoCD reconciles declared manifests against live cluster state; it never executes test suites. It is tempting because testing often follows deployment in a pipeline, but unit tests run in CI stages such as GitHub Actions or Jenkins before ArgoCD syncs anything.

  • ✗

    Managing secrets using Kubernetes Secrets

    Why it's wrong here

    ArgoCD deploys Kubernetes Secrets as ordinary manifests but provides no secret-management capability of its own. It is tempting because secrets do appear in GitOps repositories, yet dedicated vaults such as HashiCorp Vault or External Secrets Operator handle encryption and rotation.

Go deeper

Related to this question

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on KCNA

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are features of ArgoCD that support GitOps principles?

hard
  • A.Automatic secret management
  • ✓ B.Health status visualization of applications
  • C.Built-in template engine for generating manifests
  • ✓ D.Automated sync to desired state defined in Git
  • E.Self-healing by reverting manual changes

Why B: Option B is correct because ArgoCD provides a real-time health status visualization of applications, showing whether Kubernetes resources are Healthy, Progressing, Degraded, or Missing, which supports GitOps observability of the live state versus the desired state. Option D is correct because ArgoCD's core GitOps capability is automated sync, continuously reconciling the cluster to the desired state declared in Git (via auto-sync policies and sync policies like Automated with Prune/SelfHeal). Option A is not a native ArgoCD feature; secret management is typically handled by external tools such as Sealed Secrets, SOPS, or Vault, not ArgoCD itself. Option C is incorrect because ArgoCD is not a template engine; it consumes rendered manifests or integrates with tools like Helm, Kustomize, or Jsonnet rather than generating manifests itself. Option E is not marked correct here because self-healing is part of the automated sync policy rather than a standalone listed feature in this question's intended answer set.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.