Courseiva

KCNA Cloud Native Application Delivery Practice Question

Which TWO statements about GitOps are correct?

⚠ Common exam trap

KCNA often tests the misconception that GitOps is synonymous with CI/CD or requires specific tooling like container registries, when the defining characteristics are simply Git as source of truth and automated reconciliation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Git is the single source of truth for desired system state

Option B is correct because GitOps fundamentally uses Git as the single source of truth: the desired state of the system (manifests, Helm charts, Kustomize overlays) is declaratively stored and versioned in a Git repository, and that repository is the authoritative reference for what should be deployed. Option C is correct because a GitOps operator (such as Argo CD or Flux) continuously watches the Git repository and the cluster, automatically reconciling the live cluster state to match the desired state declared in Git, correcting any drift. Option A is not required: GitOps can deploy non-containerized resources and does not mandate a container registry, though one is often used alongside it. Option D is wrong because CI pipelines are still needed to build, test, and produce artifacts, even though GitOps handles the continuous delivery/deployment portion. Option E is wrong because GitOps explicitly forbids direct imperative changes via kubectl; all changes must flow through Git commits and pull requests so the repository remains the source of truth.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    GitOps requires a container registry

    Why it's wrong here

    GitOps does not mandate a container registry; it can deploy Helm charts, Kustomize manifests or raw YAML to clusters, with images pulled from any source. A registry is correct when the workload itself is containerised and images must be stored and versioned.

  • ✓

    Git is the single source of truth for desired system state

    Why this is correct

    Git stores the declarative desired state, and an automated controller continuously reconciles the live cluster towards that committed state, satisfying GitOps's requirement for a single authoritative source. This enables versioned, auditable changes and rollback via Git history, rather than imperative cluster commands.

  • ✓

    The cluster state is automatically reconciled with the Git repository

    Why this is correct

    Continuous reconciliation is the defining mechanism: an agent such as Argo CD or Flux watches the Git repository and applies any divergence to the cluster, so the declared state in Git becomes the enforced desired state. This satisfies the stem's requirement for automatic convergence without manual intervention.

  • ✗

    GitOps eliminates the need for CI pipelines

    Why it's wrong here

    GitOps still relies on CI pipelines to build, test and publish artefacts; the Git repository becomes the desired-state source that a controller reconciles. It is tempting because GitOps shifts deployment control into Git, and CI remains the correct tool for producing validated images before that.

  • ✗

    Changes are made directly to the cluster using kubectl

    Why it's wrong here

    Direct kubectl changes bypass Git as the single source of truth, so the cluster state diverges from the declared repository and reconciliation cannot detect drift. It is tempting because kubectl is the standard tool for imperative troubleshooting, and it would be correct for one-off debugging, not for GitOps-managed workloads.

Go deeper

Related to this question

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.