KCNA Cloud Native Architecture Practice Question
You are a platform engineer at a fast-growing startup. The company runs a Kubernetes cluster with 50 worker nodes for its production microservices. Recently, the operations team has been struggling with manual configuration drift: developers SSH into nodes to install debugging tools, and some nodes have different kernel parameters or installed packages. This has caused intermittent outages when a pod is scheduled onto a non-standard node. The CTO wants a solution that ensures each node is identical, immutable, and reproducible. The cluster uses kubeadm for bootstrapping and runs on AWS EC2. Which approach best achieves the goal of immutable nodes?
⚠ Common exam trap
Many exam-takers confuse configuration management (Option A) with immutability, not realizing that periodic enforcement still allows drift and does not guarantee identical nodes at all times.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a golden AMI using Packer with all required configurations, then use Auto Scaling groups with a launch template that references the AMI and enable instance refresh for updates.
It uses a golden AMI built with Packer to create identical, immutable nodes that are reproducible via Auto Scaling groups and launch templates. This approach ensures that every EC2 instance launched has the exact same kernel parameters, packages, and configuration, eliminating configuration drift. Instance refresh allows rolling updates to the AMI without manual intervention, aligning with the goal of immutable infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a configuration management tool like Ansible to enforce desired state on each node via periodic runs.
Why it's wrong here
Ansible converges existing nodes in place, so drift is corrected only at run time and nodes remain mutable between runs, failing the immutability and reproducibility requirement. It is tempting because Ansible does enforce desired state, which would be correct for managing long-lived mutable servers rather than replacing them.
- ✗
Apply Kubernetes node labels and taints to categorize nodes and prevent workloads from running on non-standard nodes.
Why it's wrong here
Labels and taints only influence scheduling decisions; they neither rebuild nor verify node state, so SSH-installed packages and altered kernel parameters persist and drift continues. They suit steering workloads across deliberately heterogeneous nodes, such as dedicating GPU or spot capacity, not enforcing identical, reproducible machine images.
- ✓
Create a golden AMI using Packer with all required configurations, then use Auto Scaling groups with a launch template that references the AMI and enable instance refresh for updates.
Why this is correct
Packer builds a golden AMI containing every package and kernel parameter, and Auto Scaling groups with instance refresh replace nodes from that image, eliminating SSH drift. Nodes become identical, immutable and reproducible, satisfying the CTO's requirement on EC2.
- ✗
Deploy a DaemonSet that runs a privileged container to enforce node configuration and remove debugging tools.
Why it's wrong here
A DaemonSet mutates running nodes rather than replacing them, so nodes remain mutable and drift can reappear if the pod fails or is removed. It is tempting because DaemonSets do run on every node, which would be correct for deploying a monitoring or logging agent cluster-wide.
Go deeper
Related to this question
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.