pencils ready ✎

Kubernetes MCQs multiple-choice questions with answers & explanations

All 20 Kubernetes quiz questions on one page. Pick an answer in your head, then open Show answer to check it and read why. Want a score and a timer? Take them as a quiz instead.

  1. 1.

    If a Service manifest does not set spec.type, which type does it get?

    easy
    1. ANodePort
    2. BClusterIP
    3. CLoadBalancer
    4. DExternalName
    Show answer

    Answer: B (ClusterIP)

    ClusterIP is the default: a virtual IP reachable only inside the cluster. NodePort and LoadBalancer build on it to expose the Service externally, and ExternalName is just a DNS CNAME with no proxying.

  2. 2.

    A running container starts failing its readiness probe. What does Kubernetes do?

    easy
    1. AThe kubelet restarts the container
    2. BThe pod is evicted and rescheduled
    3. CThe pod stops receiving Service traffic
    4. DThe Deployment rolls back automatically
    Show answer

    Answer: C (The pod stops receiving Service traffic)

    A failed readiness probe sets the pod’s Ready condition to false, so it is removed from the EndpointSlices of matching Services, but the container keeps running. Restarting is what a failed liveness probe does; readiness never causes eviction or a rollback.

  3. 3.

    A pod has a single container with these resources. What is its QoS class?

    mid
    resources:
      requests: { cpu: 500m, memory: 256Mi }
      limits:   { cpu: 500m, memory: 512Mi }
    1. ABurstable
    2. BGuaranteed
    3. CBestEffort
    4. DNone until you set qosClass
    Show answer

    Answer: A (Burstable)

    Guaranteed requires requests to equal limits for both CPU and memory in every container; here memory differs, so the pod is Burstable. BestEffort means no requests or limits at all, and the class is always derived by Kubernetes, never set by you.

  4. 4.

    During a rollout of this Deployment, what is the maximum number of pods, and the minimum number that must stay available?

    hard
    spec:
      replicas: 10
      strategy:
        type: RollingUpdate   # maxSurge and maxUnavailable left at their defaults
    1. A12 total, at least 7 available
    2. B13 total, at least 7 available
    3. C12 total, at least 8 available
    4. D13 total, at least 8 available
    Show answer

    Answer: D (13 total, at least 8 available)

    Both settings default to 25%. maxSurge rounds up (2.5 becomes 3, so up to 13 pods), while maxUnavailable rounds down (2.5 becomes 2, so at least 8 stay available). The rounding is deliberately conservative in both directions.

  5. 5.

    kubectl describe pod shows a container’s last state as Terminated with reason OOMKilled. Which exit code do you expect?

    easy
    1. A1
    2. B143
    3. C137
    4. D126
    Show answer

    Answer: C (137)

    The kernel OOM killer sends SIGKILL, and 128 + 9 = 137. Exit code 143 is SIGTERM (128 + 15), usually a normal shutdown; 1 is a generic application error; 126 means the command could not be executed.

  6. 6.

    This NetworkPolicy ingress rule has two entries in from. Which sources may reach the selected pods?

    hard
    ingress:
      - from:
          - namespaceSelector:
              matchLabels: { user: alice }
          - podSelector:
              matchLabels: { role: client }
    1. AOnly role=client pods inside namespaces labeled user=alice
    2. Brole=client pods in this namespace, or any pod in user=alice namespaces
    3. CAny pod in any namespace, because the two selectors cancel out
    4. DOnly role=client pods in this namespace; the namespace selector is ignored
    Show answer

    Answer: B (role=client pods in this namespace, or any pod in user=alice namespaces)

    Separate entries in from are ORed: pods labeled role=client in the policy’s own namespace, or any pod in a namespace labeled user=alice. Putting namespaceSelector and podSelector in the same entry (no second dash) would AND them, which is the first option.

  7. 7.

    By default, how does the API server store Secret values in etcd?

    easy
    1. AEncrypted with a key generated when the cluster is created
    2. BHashed, so they can only be compared, not read
    3. CUnencrypted, unless encryption at rest is configured
    4. DEncrypted by the kubelet before they are sent
    Show answer

    Answer: C (Unencrypted, unless encryption at rest is configured)

    Secrets are stored unencrypted in etcd by default; the base64 in manifests is just encoding. You must configure encryption at rest (an EncryptionConfiguration, ideally with a KMS provider) and restrict access to etcd and its backups.

  8. 8.

    A StatefulSet db with volumeClaimTemplates is scaled from 3 replicas to 1, with default settings. What happens to the PVCs data-db-1 and data-db-2?

    mid
    1. AThey are deleted along with their pods
    2. BThey are rebound to the remaining pod db-0
    3. CThey are released and their PVs recycled
    4. DThey are kept and reused on scale-up
    Show answer

    Answer: D (They are kept and reused on scale-up)

    By default, scaling down or deleting a StatefulSet does not delete its PVCs, to protect data. Scaling back up recreates db-1 and db-2, which reattach to the same claims. persistentVolumeClaimRetentionPolicy can change this to Delete.

  9. 9.

    You add the taint maintenance=true:NoExecute to a node. What happens to running pods on it that have no matching toleration?

    mid
    1. AThey are evicted from the node
    2. BNothing; taints only affect new scheduling
    3. CThey keep running but are marked not ready
    4. DThey are evicted only after the node reboots
    Show answer

    Answer: A (They are evicted from the node)

    NoExecute both blocks scheduling and evicts running pods that don’t tolerate it. Pods that tolerate it with tolerationSeconds stay only that long. The "only new scheduling" behavior describes NoSchedule.

  10. 10.

    Which of these is not limited by a PodDisruptionBudget?

    mid
    1. Akubectl drain evicting pods from a node
    2. BA cluster autoscaler scale-down
    3. Ckubectl delete pod on one of the pods
    4. DA direct call to the Eviction API
    Show answer

    Answer: C (kubectl delete pod on one of the pods)

    PDBs are enforced by the Eviction API, which kubectl drain and the cluster autoscaler use. Deleting a pod directly bypasses the budget entirely, as do involuntary disruptions like node crashes.

  11. 11.

    An HPA targets 60% average CPU utilization. The Deployment has 3 replicas averaging 90%. How many replicas will the HPA request, ignoring stabilization windows?

    mid
    1. A4
    2. B5
    3. C6
    4. D9
    Show answer

    Answer: B (5)

    The HPA computes ceil(currentReplicas × currentMetric / target) = ceil(3 × 90 / 60) = ceil(4.5) = 5. The ratio of 1.5 is well outside the default 10% tolerance, so it acts, within minReplicas and maxReplicas.

  12. 12.

    What does a DNS lookup of a headless Service (clusterIP: None) with a selector return?

    mid
    1. AOne virtual IP that load-balances the pods
    2. BA CNAME record pointing at a node name
    3. CNothing; headless Services have no DNS
    4. DThe IP addresses of its ready pods
    Show answer

    Answer: D (The IP addresses of its ready pods)

    A headless Service has no virtual IP, so DNS returns A/AAAA records for the ready pods behind it. That’s what gives StatefulSet pods per-pod DNS names and allows client-side load balancing. A CNAME is what an ExternalName Service returns.

  13. 13.

    A RoleBinding in namespace dev references the built-in ClusterRole view. What does its subject get?

    mid
    1. ARead access only within dev
    2. BRead access in every namespace
    3. CNothing; RoleBindings cannot use ClusterRoles
    4. DRead access to cluster-scoped resources only
    Show answer

    Answer: A (Read access only within dev)

    A RoleBinding can reference a ClusterRole, and the permissions then apply only inside the binding’s namespace. That is the standard way to reuse view, edit or admin. Granting them across all namespaces requires a ClusterRoleBinding.

  14. 14.

    How do you declare a native sidecar container, stable since Kubernetes v1.33?

    mid
    1. AA containers entry with sidecar: true
    2. BAn init container with restartPolicy: Always
    3. CA containers entry with restartPolicy: Always
    4. DAny container once shareProcessNamespace is set
    Show answer

    Answer: B (An init container with restartPolicy: Always)

    Native sidecars are init containers with restartPolicy: Always: they start before the app containers, keep running, stop after them and don’t block Job completion. There is no sidecar field, and shareProcessNamespace only shares the process namespace.

  15. 15.

    You apply a valid Ingress, but no traffic is routed and it never gets an address. What is the most likely cause?

    easy
    1. ANo ingress controller handles its class
    2. BIngress only works with headless Services
    3. CIngress needs a LoadBalancer annotation
    4. DThe Ingress API was removed from Kubernetes
    Show answer

    Answer: A (No ingress controller handles its class)

    An Ingress is only configuration; an ingress controller matching its ingressClassName (or the default class) must be running to implement it. The Ingress API is frozen but still GA and not being removed, and it routes to normal Services.

  16. 16.

    Which of these is not required by the Pod Security Standards restricted profile?

    hard
    1. ArunAsNonRoot: true
    2. BallowPrivilegeEscalation: false
    3. CDropping ALL capabilities
    4. DreadOnlyRootFilesystem: true
    Show answer

    Answer: D (readOnlyRootFilesystem: true)

    restricted requires non-root, no privilege escalation, dropping ALL capabilities (only NET_BIND_SERVICE may be added back), a RuntimeDefault or Localhost seccomp profile and limited volume types. A read-only root filesystem is good practice but not part of the profile.

  17. 17.

    A pod is Pending with 0/3 nodes are available: 3 Insufficient memory, yet kubectl top nodes shows every node at about 40% memory. What is the most likely explanation?

    mid
    1. Ametrics-server is reporting stale data
    2. BThe scheduler compares requests, not usage
    3. CThe pod has no memory limit set
    4. DThe kubelet always reserves 60% of node memory
    Show answer

    Answer: B (The scheduler compares requests, not usage)

    The scheduler places pods by comparing their requests with each node’s allocatable capacity minus the requests of pods already there. Nodes can be "full" of requests while actual usage is low, which is a sign of over-requesting.

  18. 18.

    A container uses image: nginx:latest and does not set imagePullPolicy. Which pull policy does Kubernetes apply?

    easy
    1. AIfNotPresent
    2. BNever
    3. COnFailure
    4. DAlways
    Show answer

    Answer: D (Always)

    When the tag is :latest or omitted and no policy is given, it defaults to Always; any other tag defaults to IfNotPresent. OnFailure is a restart policy, not a pull policy.

  19. 19.

    Which restartPolicy values are allowed in a Job’s pod template?

    easy
    1. AAlways only
    2. BNever only
    3. COnFailure or Never
    4. DAny value, including Always
    Show answer

    Answer: C (OnFailure or Never)

    A Job runs pods to completion, so its pod template must use OnFailure or Never. Always would restart containers forever and the Job could never finish.

  20. 20.

    A Deployment’s new pods never become ready, and progressDeadlineSeconds passes. What does Kubernetes do?

    mid
    1. AReports ProgressDeadlineExceeded, nothing more
    2. BRolls back to the previous ReplicaSet automatically
    3. CDeletes the new ReplicaSet and all of its pods
    4. DScales the whole Deployment down to zero
    Show answer

    Answer: A (Reports ProgressDeadlineExceeded, nothing more)

    Kubernetes takes no action on a stalled rollout other than setting the Progressing condition to false with reason ProgressDeadlineExceeded. Rolling back is up to you (kubectl rollout undo) or to tooling that watches that condition.

esc