KCNA Cloud Native Application Delivery Practice Question
Which TWO statements about GitOps are correct?
⚠ Common exam trap
KCNA often tests the misconception that GitOps is synonymous with CI/CD or requires specific tooling like container registries, when the defining characteristics are simply Git as source of truth and automated reconciliation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Git is the single source of truth for desired system state
Option B is correct because GitOps fundamentally uses Git as the single source of truth: the desired state of the system (manifests, Helm charts, Kustomize overlays) is declaratively stored and versioned in a Git repository, and that repository is the authoritative reference for what should be deployed. Option C is correct because a GitOps operator (such as Argo CD or Flux) continuously watches the Git repository and the cluster, automatically reconciling the live cluster state to match the desired state declared in Git, correcting any drift. Option A is not required: GitOps can deploy non-containerized resources and does not mandate a container registry, though one is often used alongside it. Option D is wrong because CI pipelines are still needed to build, test, and produce artifacts, even though GitOps handles the continuous delivery/deployment portion. Option E is wrong because GitOps explicitly forbids direct imperative changes via kubectl; all changes must flow through Git commits and pull requests so the repository remains the source of truth.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
GitOps requires a container registry
Why it's wrong here
GitOps does not mandate a container registry; it can deploy Helm charts, Kustomize manifests or raw YAML to clusters, with images pulled from any source. A registry is correct when the workload itself is containerised and images must be stored and versioned.
- ✓
Git is the single source of truth for desired system state
Why this is correct
Git stores the declarative desired state, and an automated controller continuously reconciles the live cluster towards that committed state, satisfying GitOps's requirement for a single authoritative source. This enables versioned, auditable changes and rollback via Git history, rather than imperative cluster commands.
- ✓
The cluster state is automatically reconciled with the Git repository
Why this is correct
Continuous reconciliation is the defining mechanism: an agent such as Argo CD or Flux watches the Git repository and applies any divergence to the cluster, so the declared state in Git becomes the enforced desired state. This satisfies the stem's requirement for automatic convergence without manual intervention.
- ✗
GitOps eliminates the need for CI pipelines
Why it's wrong here
GitOps still relies on CI pipelines to build, test and publish artefacts; the Git repository becomes the desired-state source that a controller reconciles. It is tempting because GitOps shifts deployment control into Git, and CI remains the correct tool for producing validated images before that.
- ✗
Changes are made directly to the cluster using kubectl
Why it's wrong here
Direct kubectl changes bypass Git as the single source of truth, so the cluster state diverges from the declared repository and reconciliation cannot detect drift. It is tempting because kubectl is the standard tool for imperative troubleshooting, and it would be correct for one-off debugging, not for GitOps-managed workloads.
Go deeper
Related to this question
Learn chapter
Container Orchestration Essentials
Key term
GitOps
GitOps is a way to manage and automate cloud infrastructure and applications by using a Git repository as the single source of truth, where all changes are made through pull requests and automatically applied by a software agent.
Key term
Helm Charts
Helm Charts are packages of pre-configured Kubernetes resources that let you install, upgrade, and manage complex applications on a Kubernetes cluster with a single command.
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.