Linux Foundation KCNA Exam Practice Questions (P. 1)
- Full Access (333 questions)
- One Year of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
What native runtime is Open Container Initiative (OCI) compliant?
- ArunCMost Voted
- BrunV
- Ckata-containers
- Dgvisor
Correct Answer:
A
A
GPT
Absolutely! runC is the fundamental choice here as it’s straight-up OCI compliant, focusing on spinning up containers according to the standards set by the Open Container Initiative. It’s essentially the core engine that gets this job done under the hood. This makes it critical for anyone diving into container architecture since understanding these foundational tools and their compliance status is key. RunC sets the stage for other tools and frameworks to build upon, ensuring alignment with OCI specs.
send
light_mode
delete
Question #2
Which API object is the recommended way to run a scalable, stateless application on your cluster?
- AReplicaSet
- BDeploymentMost Voted
- CDaemonSet
- DPod
Correct Answer:
B
B
GPT
Deployments in Kubernetes are the best way to manage stateless applications that need scaling and rolling updates. They leverage ReplicaSets, yet they allow for more robust update mechanisms, rollback capabilities, and declarative configuration updates which make managing stateless applications more efficient and reliable compared to directly using ReplicaSets or Pods.
send
light_mode
delete
Question #3
A CronJob is scheduled to run by a user every one hour. What happens in the cluster when it's time for this CronJob to run?
- AKubelet watches API Server for CronJob objects. When it's time for a Job to run, it runs the Pod directly.
- BKube-scheduler watches API Server for CronJob objects, and this is why it's called kube-scheduler.
- CCronJob controller component creates a Pod and waits until it finishes to run.
- DCronJob controller component creates a Job. Then the Job controller creates a Pod and waits until it finishes to run.
Correct Answer:
D
D
GPT
The correct answer is D and it has a solid, straightforward explanation. When a CronJob is set to run, the CronJob controller gets triggered. Instead of directly creating a Pod, the CronJob controller spins up a Job. It's the Job controller's turn afterwards to handle the creation of the Pod necessary to execute the task. This two-step process ensures jobs from a CronJob are efficiently managed and tracked, aligning with Kubernetes' robust orchestration capabilities.
send
light_mode
delete
Question #4
What is the purpose of the kubelet component within a Kubernetes cluster?
- AA dashboard for Kubernetes Clusters that allows management and troubleshooting of applications.
- BA network proxy that runs on each node in your cluster, implementing part of the Kubernetes Service concept.
- CA component that watches for newly created Pods with no assigned node, and selects a node for them to run on.
- DAn agent that runs on each node in the cluster. It makes sure that containers are running in a Pod.Most Voted
Correct Answer:
D
D
GPT
The kubelet is super critical because it operates on each node in your Kubernetes cluster, earnestly ensuring that containers are up and kicking within the Pods. It’s like having a diligent overseer on every node that keeps things ticking according to plans set out in the PodSpecs. This is essential for maintaining the desired state and consistent operations across all nodes.
send
light_mode
delete
Question #5
What is the default value for authorization-mode in Kubernetes API server?
- A--authorization-mode=RBAC
- B--authorization-mode=AlwaysAllowMost Voted
- C--authorization-mode=AlwaysDeny
- D--authorization-mode=ABAC
Correct Answer:
B
B
GPT
Absolutely right. When you fire up the Kubernetes API server without specifying the authorization mode, it defaults to "--authorization-mode=AlwaysAllow." This setup is basic, assuming no initial restrictions on requests processed by the server, ideal for specific test or low-security environments. It's essential to modify this in production environments to enforce authorization policies effectively, typically to something more secure like RBAC.
send
light_mode
delete
Question #6
Let's assume that an organization needs to process large amounts of data in bursts, on a cloud-based Kubernetes cluster. For instance: each Monday morning, they need to run a batch of 1000 compute jobs of 1 hour each, and these jobs must be completed by Monday night. What's going to be the most cost-effective method?
- ARun a group of nodes with the exact required size to complete the batch on time, and use a combination of taints, tolerations, and nodeSelectors to reserve these nodes to the batch jobs.
- BLeverage the Kubernetes Cluster Autoscaler to automatically start and stop nodes as they're needed.
- CCommit to a specific level of spending to get discounted prices (with e.g. “reserved instances” or similar mechanisms).
- DUse PriorityСlasses so that the weekly batch job gets priority over other workloads running on the cluster, and can be completed on time.
Correct Answer:
B
B
GPT
For the given scenario, leveraging the Kubernetes Cluster Autoscaler as the most cost-effective method is quite apt. This tool dynamically adjusts the number of nodes in a cluster based on the needs, scaling up when demand spikes each Monday, and scaling down afterwards, minimizing costs when less compute power is needed. This avoids unnecessary expenditure on idle resources outside of peak times, making it a smart choice for bursty workloads like those described.
send
light_mode
delete
Question #7
What is a Kubernetes service with no cluster IP address called?
- AHeadless Service
- BNodeless Service
- CIPLess Service
- DSpecless Service
Correct Answer:
A
A
GPT
Certainly! In the context like Kubernetes, when dealing with services that bypass the allocation of a cluster IP to directly interface with specific pods, the term used is "Headless Service." This means the service is configured with 'clusterIP: None,' which allows it to connect directly with the Pods' DNS rather than through a typical service IP. This is ideal for scenarios requiring direct pod communication without a load-balanced intermediary.
send
light_mode
delete
Question #8
CI/CD stands for:
- AContinuous Information / Continuous Development
- BContinuous Integration / Continuous Development
- CCloud Integration / Cloud Development
- DContinuous Integration / Continuous DeploymentMost Voted
Correct Answer:
D
D
GPT
**Professor's Comment:**
The correct answer is D, which stands for Continuous Integration and Continuous Deployment. This is a key concept in DevOps where code modifications are continuously integrated and automatically tested, ensuring that new changes are deployed seamlessly into production. This approach boosts efficiency and minimizes bugs, making the development cycle faster and more reliable.
send
light_mode
delete
Question #9
What default level of protection is applied to the data in Secrets in the Kubernetes API?
- AThe values use AES Symmetric Encryption
- BThe values are stored in plain text
- CThe values are encoded with SHA256 hashes
- DThe values are base64 encodedMost Voted
Correct Answer:
D
D
GPT
Definitely, in Kubernetes, when you're working with Secrets, the data isn't encrypted by default. What happens is, it's merely base64 encoded. So, D is spot on! This encoding is not a form of encryption or hashing; it's just a method used to represent binary data in an ASCII string format which can be especially handy with data that might cause issues in environments that expect certain data formats. Keep this in mind, because understanding this will be crucial for managing sensitive data securely in K8s!
send
light_mode
delete
Question #10
What function does kube-proxy provide to a cluster?
- AImplementing the Ingress resource type for application traffic.
- BForwarding data to the correct endpoints for Services.Most Voted
- CManaging data egress from the cluster nodes to the network.
- DManaging access to the Kubernetes API.
Correct Answer:
B
B
GPT
Kube-proxy is crucial for its role in managing how network traffic is forwarded to the correct pods based on service definitions. It listens to the Kubernetes API server for new services and endpoints and updates the relevant forwarding rules. This ensures network requests are sent to the right service endpoints, effectively allowing pods to communicate both internally and externally as needed.
send
light_mode
delete
All Pages
