Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Linux Foundation Certified Kubernetes Administrator CKA Exam Questions

Page: 1 / 9 Total 83 questions

Want more questions? Get Premium Access.

Question 1

SIMULATION

You must connect to the correct host.

Failure to do so may result in a zero score.

[candidate@base] $ ssh Cka000037

Context

A legacy app needs to be integrated into the Kubernetes built-in logging architecture (i.e.

kubectl logs). Adding a streaming co-located container is a good and common way to

accomplish this requirement.

Task

Update the existing Deployment synergy-leverager, adding a co-located container named sidecar using the busybox:stable image to the existing Pod . The new co-located container has to run the following command:

/bin/sh -c "tail -n+1 -f /var/log/syne

rgy-leverager.log"

Use a Volume mounted at /var/log to make the log file synergy-leverager.log available to the co-

located container .

Do not modify the specification of the existing container other than adding the required volume mount .

Failure to do so may result in a reduced score.

Correct Answer: A, A
Explanation:

Task Summary

SSH into the correct node: cka000037

Modify existing deployment synergy-leverager

Add a sidecar container:

Name: sidecar

Image: busybox:stable

Command:

/bin/sh -c 'tail -n+1 -f /var/log/synergy-leverager.log'

Use a shared volume mounted at /var/log

Don't touch existing container config except adding volume mount

Step-by-Step Solution

1 SSH into the correct node

ssh cka000037

Skipping this will result in a zero score.

2 Edit the deployment

kubectl edit deployment synergy-leverager

This opens the deployment YAML in your default editor (vi or similar).

3 Modify the spec as follows

Inside the spec.template.spec, do these 3 things:


Question 2

SIMULATION

Score: 4%

Task

Schedule a pod as follows:

* Name: nginx-kusc00401

* Image: nginx

* Node selector: disk=ssd

Correct Answer: A. See the solution below
Explanation:

Solution:

#yaml

apiVersion: v1

kind: Pod

metadata:

name: nginx-kusc00401

spec:

containers:

- name: nginx

image: nginx

imagePullPolicy: IfNotPresent

nodeSelector:

disk: spinning

#

kubectl create -f node-select.yaml


Question 3

SIMULATION

Given a partially-functioning Kubernetes cluster, identify symptoms of failure on the cluster.

Determine the node, the failing service, and take actions to bring up the failed service and restore the health of the cluster. Ensure that any changes are made permanently.

You can ssh to the relevant I nodes (bk8s-master-0 or bk8s-node-0) using:

[student@node-1] $ ssh

You can assume elevated privileges on any node in the cluster with the following command:

[student@nodename] $ | sudo --i

Correct Answer: A. See the solution below
Explanation:

solution


Question 4

SIMULATION

Score: 4%

Task

Scale the deployment presentation to 6 pods.

Correct Answer: A. See the solution below
Explanation:

Solution:

kubectl get deployment

kubectl scale deployment.apps/presentation --replicas=6


Question 5

SIMULATION

Score: 4%

Task

Check to see how many nodes are ready schedulable (not including nodes tainted NoSchedule ) and write the number to /opt/KUSC00402/kusc00402.txt.

Correct Answer: A. See the solution below
Explanation:

Solution:

kubectl describe nodes | grep ready|wc -l

kubectl describe nodes | grep -i taint | grep -i noschedule |wc -l

echo 3 > /opt/KUSC00402/kusc00402.txt

#

kubectl get node | grep -i ready |wc -l

# taintsnoSchedule

kubectl describe nodes | grep -i taints | grep -i noschedule |wc -l

#

echo 2 > /opt/KUSC00402/kusc00402.txt


Question 6

SIMULATION

Score: 7%

Task

Create a new nginx Ingress resource as follows:

* Name: ping

* Namespace: ing-internal

* Exposing service hi on path /hi using service port 5678

Correct Answer: A. See the solution below
Explanation:

Solution:

vi ingress.yaml

#

apiVersion: networking.k8s.io/v1

kind: Ingress

metadata:

name: ping

namespace: ing-internal

spec:

rules:

- http:

paths:

- path: /hi

pathType: Prefix

backend:

service:

name: hi

port:

number: 5678

#

kubectl create -f ingress.yaml


Question 7

SIMULATION

Monitor the logs of pod foo and:

Extract log lines corresponding to error

unable-to-access-website

Write them to/opt/KULM00201/foo

Correct Answer: A. See the solution below
Explanation:

solution

Step 0: Set the correct Kubernetes context

If you're given a specific context (k8s in this case), you must switch to it:

kubectl config use-context k8s

Skipping this can cause you to work in the wrong cluster/namespace and cost you marks.

Step 1: Identify the namespace of the pod foo

First, check if foo is running in a specific namespace or in the default namespace.

kubectl get pods --all-namespaces | grep foo

Assume the pod is in the default namespace if no namespace is mentioned.

Step 2: Confirm pod foo exists and is running

kubectl get pod foo

You should get output similar to:

NAME READY STATUS RESTARTS AGE

foo 1/1 Running 0 1h

If the pod is not running, logs may not be available.

Step 3: View logs and filter specific error lines

We're looking for log lines that contain:

unable-to-access-website

Command:

kubectl logs foo | grep 'unable-to-access-website'

Step 4: Write the filtered log lines to a file

Redirect the output to the required path:

kubectl logs foo | grep 'unable-to-access-website' > /opt/KULM00201/foo

This creates or overwrites the file /opt/KULM00201/foo with the filtered logs.

You may need sudo if /opt requires elevated permissions. But in most exam environments, you're already the root or privileged user.

Step 5: Verify the output file (optional but smart)

Check that the file was created and has the correct content:

cat /opt/KULM00201/foo

Final Answer Summary:

kubectl config use-context k8s

kubectl logs foo | grep 'unable-to-access-website' > /opt/KULM00201/foo


Question 8

SIMULATION

Score: 4%

Task

Set the node named ek8s-node-1 as unavailable and reschedule all the pods running on it.

Correct Answer: A. See the solution below
Explanation:

SOLUTION:

[student@node-1] > ssh ek8s

kubectl cordon ek8s-node-1

kubectl drain ek8s-node-1 --delete-local-data --ignore-daemonsets --force


Question 9

SIMULATION

Score: 7%

Task

First, create a snapshot of the existing etcd instance running at https://127.0.0.1:2379, saving the snapshot to /srv/data/etcd-snapshot.db.

Next, restore an existing, previous snapshot located at /var/lib/backup/etcd-snapshot-previo us.db

Correct Answer: A. See the solution below
Explanation:

Solution:

#backup

ETCDCTL_API=3 etcdctl --endpoints='https://127.0.0.1:2379' --cacert=/opt/KUIN000601/ca.crt --cert=/opt/KUIN000601/etcd-client.crt --key=/opt/KUIN000601/etcd-client.key snapshot save /etc/data/etcd-snapshot.db

#restore

ETCDCTL_API=3 etcdctl --endpoints='https://127.0.0.1:2379' --cacert=/opt/KUIN000601/ca.crt --cert=/opt/KUIN000601/etcd-client.crt --key=/opt/KUIN000601/etcd-client.key snapshot restore /var/lib/backup/etcd-snapshot-previoys.db


Question 10

SIMULATION

Create a deployment spec file that will:

Launch 7 replicas of the nginx Image with the labelapp_runtime_stage=dev

deployment name: kual00201

Save a copy of this spec file to /opt/KUAL00201/spec_deployment.yaml

(or /opt/KUAL00201/spec_deployment.json).

When you are done, clean up (delete) any new Kubernetes API object that you produced during this task.

Correct Answer: A. See the solution below
Explanation:

solution