Kubernetes MCQs multiple-choice questions with answers & explanations
All 20 Kubernetes quiz questions on one page. Pick an answer in your head, then open Show answer to check it and read why. Want a score and a timer? Take them as a quiz instead.
- 1.easy
If a Service manifest does not set
spec.type, which type does it get?- A
NodePort - B
ClusterIP - C
LoadBalancer - D
ExternalName
Show answer
Answer: B (
ClusterIP)ClusterIPis the default: a virtual IP reachable only inside the cluster.NodePortandLoadBalancerbuild on it to expose the Service externally, andExternalNameis just a DNS CNAME with no proxying. - A
- 2.easy
A running container starts failing its readiness probe. What does Kubernetes do?
- AThe kubelet restarts the container
- BThe pod is evicted and rescheduled
- CThe pod stops receiving Service traffic
- DThe Deployment rolls back automatically
Show answer
Answer: C (The pod stops receiving Service traffic)
A failed readiness probe sets the pod’s
Readycondition to false, so it is removed from the EndpointSlices of matching Services, but the container keeps running. Restarting is what a failed liveness probe does; readiness never causes eviction or a rollback. - 3.mid
A pod has a single container with these resources. What is its QoS class?
resources: requests: { cpu: 500m, memory: 256Mi } limits: { cpu: 500m, memory: 512Mi }- A
Burstable - B
Guaranteed - C
BestEffort - DNone until you set
qosClass
Show answer
Answer: A (
Burstable)Guaranteedrequires requests to equal limits for both CPU and memory in every container; here memory differs, so the pod isBurstable.BestEffortmeans no requests or limits at all, and the class is always derived by Kubernetes, never set by you. - A
- 4.hard
During a rollout of this Deployment, what is the maximum number of pods, and the minimum number that must stay available?
spec: replicas: 10 strategy: type: RollingUpdate # maxSurge and maxUnavailable left at their defaults- A12 total, at least 7 available
- B13 total, at least 7 available
- C12 total, at least 8 available
- D13 total, at least 8 available
Show answer
Answer: D (13 total, at least 8 available)
Both settings default to 25%.
maxSurgerounds up (2.5 becomes 3, so up to 13 pods), whilemaxUnavailablerounds down (2.5 becomes 2, so at least 8 stay available). The rounding is deliberately conservative in both directions. - 5.easy
kubectl describe podshows a container’s last state asTerminatedwith reasonOOMKilled. Which exit code do you expect?- A1
- B143
- C137
- D126
Show answer
Answer: C (137)
The kernel OOM killer sends SIGKILL, and 128 + 9 = 137. Exit code 143 is SIGTERM (128 + 15), usually a normal shutdown; 1 is a generic application error; 126 means the command could not be executed.
- 6.hard
This NetworkPolicy ingress rule has two entries in
from. Which sources may reach the selected pods?ingress: - from: - namespaceSelector: matchLabels: { user: alice } - podSelector: matchLabels: { role: client }- AOnly
role=clientpods inside namespaces labeleduser=alice - B
role=clientpods in this namespace, or any pod inuser=alicenamespaces - CAny pod in any namespace, because the two selectors cancel out
- DOnly
role=clientpods in this namespace; the namespace selector is ignored
Show answer
Answer: B (
role=clientpods in this namespace, or any pod inuser=alicenamespaces)Separate entries in
fromare ORed: pods labeledrole=clientin the policy’s own namespace, or any pod in a namespace labeleduser=alice. PuttingnamespaceSelectorandpodSelectorin the same entry (no second dash) would AND them, which is the first option. - AOnly
- 7.easy
By default, how does the API server store Secret values in etcd?
- AEncrypted with a key generated when the cluster is created
- BHashed, so they can only be compared, not read
- CUnencrypted, unless encryption at rest is configured
- DEncrypted by the kubelet before they are sent
Show answer
Answer: C (Unencrypted, unless encryption at rest is configured)
Secrets are stored unencrypted in etcd by default; the base64 in manifests is just encoding. You must configure encryption at rest (an
EncryptionConfiguration, ideally with a KMS provider) and restrict access to etcd and its backups. - 8.mid
A StatefulSet
dbwithvolumeClaimTemplatesis scaled from 3 replicas to 1, with default settings. What happens to the PVCsdata-db-1anddata-db-2?- AThey are deleted along with their pods
- BThey are rebound to the remaining pod
db-0 - CThey are released and their PVs recycled
- DThey are kept and reused on scale-up
Show answer
Answer: D (They are kept and reused on scale-up)
By default, scaling down or deleting a StatefulSet does not delete its PVCs, to protect data. Scaling back up recreates
db-1anddb-2, which reattach to the same claims.persistentVolumeClaimRetentionPolicycan change this toDelete. - 9.mid
You add the taint
maintenance=true:NoExecuteto a node. What happens to running pods on it that have no matching toleration?- AThey are evicted from the node
- BNothing; taints only affect new scheduling
- CThey keep running but are marked not ready
- DThey are evicted only after the node reboots
Show answer
Answer: A (They are evicted from the node)
NoExecuteboth blocks scheduling and evicts running pods that don’t tolerate it. Pods that tolerate it withtolerationSecondsstay only that long. The "only new scheduling" behavior describesNoSchedule. - 10.mid
Which of these is not limited by a PodDisruptionBudget?
- A
kubectl drainevicting pods from a node - BA cluster autoscaler scale-down
- C
kubectl delete podon one of the pods - DA direct call to the Eviction API
Show answer
Answer: C (
kubectl delete podon one of the pods)PDBs are enforced by the Eviction API, which
kubectl drainand the cluster autoscaler use. Deleting a pod directly bypasses the budget entirely, as do involuntary disruptions like node crashes. - A
- 11.mid
An HPA targets 60% average CPU utilization. The Deployment has 3 replicas averaging 90%. How many replicas will the HPA request, ignoring stabilization windows?
- A4
- B5
- C6
- D9
Show answer
Answer: B (5)
The HPA computes
ceil(currentReplicas × currentMetric / target)=ceil(3 × 90 / 60)=ceil(4.5)= 5. The ratio of 1.5 is well outside the default 10% tolerance, so it acts, withinminReplicasandmaxReplicas. - 12.mid
What does a DNS lookup of a headless Service (
clusterIP: None) with a selector return?- AOne virtual IP that load-balances the pods
- BA CNAME record pointing at a node name
- CNothing; headless Services have no DNS
- DThe IP addresses of its ready pods
Show answer
Answer: D (The IP addresses of its ready pods)
A headless Service has no virtual IP, so DNS returns A/AAAA records for the ready pods behind it. That’s what gives StatefulSet pods per-pod DNS names and allows client-side load balancing. A CNAME is what an
ExternalNameService returns. - 13.mid
A RoleBinding in namespace
devreferences the built-in ClusterRoleview. What does its subject get?- ARead access only within
dev - BRead access in every namespace
- CNothing; RoleBindings cannot use ClusterRoles
- DRead access to cluster-scoped resources only
Show answer
Answer: A (Read access only within
dev)A RoleBinding can reference a ClusterRole, and the permissions then apply only inside the binding’s namespace. That is the standard way to reuse
view,editoradmin. Granting them across all namespaces requires a ClusterRoleBinding. - ARead access only within
- 14.mid
How do you declare a native sidecar container, stable since Kubernetes v1.33?
- AA
containersentry withsidecar: true - BAn init container with
restartPolicy: Always - CA
containersentry withrestartPolicy: Always - DAny container once
shareProcessNamespaceis set
Show answer
Answer: B (An init container with
restartPolicy: Always)Native sidecars are init containers with
restartPolicy: Always: they start before the app containers, keep running, stop after them and don’t block Job completion. There is nosidecarfield, andshareProcessNamespaceonly shares the process namespace. - AA
- 15.easy
You apply a valid Ingress, but no traffic is routed and it never gets an address. What is the most likely cause?
- ANo ingress controller handles its class
- BIngress only works with headless Services
- CIngress needs a
LoadBalancerannotation - DThe Ingress API was removed from Kubernetes
Show answer
Answer: A (No ingress controller handles its class)
An Ingress is only configuration; an ingress controller matching its
ingressClassName(or the default class) must be running to implement it. The Ingress API is frozen but still GA and not being removed, and it routes to normal Services. - 16.hard
Which of these is not required by the Pod Security Standards
restrictedprofile?- A
runAsNonRoot: true - B
allowPrivilegeEscalation: false - CDropping
ALLcapabilities - D
readOnlyRootFilesystem: true
Show answer
Answer: D (
readOnlyRootFilesystem: true)restrictedrequires non-root, no privilege escalation, droppingALLcapabilities (onlyNET_BIND_SERVICEmay be added back), aRuntimeDefaultorLocalhostseccomp profile and limited volume types. A read-only root filesystem is good practice but not part of the profile. - A
- 17.mid
A pod is Pending with
0/3 nodes are available: 3 Insufficient memory, yetkubectl top nodesshows every node at about 40% memory. What is the most likely explanation?- Ametrics-server is reporting stale data
- BThe scheduler compares requests, not usage
- CThe pod has no memory limit set
- DThe kubelet always reserves 60% of node memory
Show answer
Answer: B (The scheduler compares requests, not usage)
The scheduler places pods by comparing their requests with each node’s allocatable capacity minus the requests of pods already there. Nodes can be "full" of requests while actual usage is low, which is a sign of over-requesting.
- 18.easy
A container uses
image: nginx:latestand does not setimagePullPolicy. Which pull policy does Kubernetes apply?- A
IfNotPresent - B
Never - C
OnFailure - D
Always
Show answer
Answer: D (
Always)When the tag is
:latestor omitted and no policy is given, it defaults toAlways; any other tag defaults toIfNotPresent.OnFailureis a restart policy, not a pull policy. - A
- 19.easy
Which
restartPolicyvalues are allowed in a Job’s pod template?- A
Alwaysonly - B
Neveronly - C
OnFailureorNever - DAny value, including
Always
Show answer
Answer: C (
OnFailureorNever)A Job runs pods to completion, so its pod template must use
OnFailureorNever.Alwayswould restart containers forever and the Job could never finish. - A
- 20.mid
A Deployment’s new pods never become ready, and
progressDeadlineSecondspasses. What does Kubernetes do?- AReports
ProgressDeadlineExceeded, nothing more - BRolls back to the previous ReplicaSet automatically
- CDeletes the new ReplicaSet and all of its pods
- DScales the whole Deployment down to zero
Show answer
Answer: A (Reports
ProgressDeadlineExceeded, nothing more)Kubernetes takes no action on a stalled rollout other than setting the
Progressingcondition to false with reasonProgressDeadlineExceeded. Rolling back is up to you (kubectl rollout undo) or to tooling that watches that condition. - AReports