Courseiva
Kubernetes Fundamentals →mediumMultiple Choice

KCNA Kubernetes Fundamentals Practice Question

You are writing a Pod manifest and need to ensure the container always pulls the newest image from the registry, even if an image with the same tag already exists on the node. Which imagePullPolicy should you set?

⚠ Common exam trap

Candidates often confuse the image tag latest with the imagePullPolicy value Always, since a tag named latest does not by itself force a registry pull.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Always

The imagePullPolicy field controls whether the kubelet consults the node's local image cache or the registry. Always is the only policy that unconditionally pulls on every container start, which is what guarantees fresh content when a mutable tag is reused. IfNotPresent and Never both allow a stale cached image to run, and Latest is not a recognized policy value.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Latest

    Why it's wrong here

    Latest is not a valid value for the imagePullPolicy field. Kubernetes accepts only Always, IfNotPresent, and Never. The word latest is a common image tag, not a pull policy, so specifying it in the imagePullPolicy field would cause the API server to reject the Pod specification during validation.

  • ✗

    Never

    Why it's wrong here

    Never instructs the kubelet to rely solely on images already present on the node and to fail container startup if the image is missing. It never contacts the registry, so it cannot satisfy the goal of always retrieving the newest image from the registry, and it would break scheduling on nodes without a cached copy.

  • ✓

    Always

    Why this is correct

    Setting imagePullPolicy to Always forces the kubelet to contact the container registry and pull the image every time a container is started, regardless of whether an image with that tag is already cached on the node. This guarantees you get the most recent image content behind a mutable tag such as latest, which is exactly the requirement in this scenario.

  • ✗

    IfNotPresent

    Why it's wrong here

    IfNotPresent tells the kubelet to use the cached image if one exists locally and only pull when it is absent. In this scenario the image with the same tag already exists on the node, so the kubelet would skip the registry entirely and start the stale cached image, failing the requirement to always fetch the newest content.

About these practice questions

This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.