Kubernetes MCQs (Multiple-Choice Questions)

Kubernetes is an open-source platform for automating the deployment, scaling, management, and operation of containerized applications. These Kubernetes MCQs cover important concepts such as Pods, Deployments, ReplicaSets, Services, ConfigMaps, Secrets, StatefulSets, DaemonSets, Jobs, CronJobs, networking, storage, scheduling, health probes, RBAC, namespaces, autoscaling, and cluster security.

Kubernetes MCQs

These Kubernetes multiple-choice questions are useful for students, DevOps engineers, cloud engineers, software developers, system administrators, and candidates preparing for technical interviews and examinations related to Kubernetes, containers, cloud computing, and DevOps.

List of Kubernetes MCQs

The following Kubernetes MCQs cover fundamental and advanced concepts involved in deploying, managing, scaling, networking, securing, and troubleshooting containerized workloads.

1. What is Kubernetes?

  1. A platform for orchestrating containerized workloads
  2. A programming language for containers
  3. A relational database system
  4. A Linux text editor

Answer: A) A platform for orchestrating containerized workloads

Explanation: Kubernetes provides APIs and controllers for deploying, scaling, networking, scheduling, and managing containerized applications across a cluster.

2. What is a Kubernetes cluster?

  1. A set of nodes managed by Kubernetes to run workloads
  2. A single container image
  3. A Dockerfile repository
  4. A single Kubernetes Service

Answer: A) A set of nodes managed by Kubernetes to run workloads

Explanation: A Kubernetes cluster consists of control-plane components and worker nodes that together manage and run containerized workloads.

3. What is a Pod in Kubernetes?

  1. The smallest deployable unit that can contain one or more containers
  2. A physical server
  3. A container image registry
  4. A Kubernetes user account

Answer: A) The smallest deployable unit that can contain one or more containers

Explanation: A Pod represents a group of one or more containers that share network and storage resources and are scheduled together.

4. What do containers within the same Pod share?

  1. Network namespace and potentially shared storage volumes
  2. Separate cluster identities
  3. Different Pod IP addresses
  4. Different Kubernetes namespaces

Answer: A) Network namespace and potentially shared storage volumes

Explanation: Containers in a Pod share the Pod's network namespace and can communicate through localhost. They can also share volumes defined for the Pod.

5. Which Kubernetes object is commonly used to manage a stateless application?

  1. Deployment
  2. PersistentVolume
  3. ConfigMap
  4. Secret

Answer: A) Deployment

Explanation: A Deployment manages a set of interchangeable Pods and provides declarative updates and ReplicaSet-based rollout management. Kubernetes documentation identifies Deployments as a good fit for stateless workloads.

6. What is a ReplicaSet primarily responsible for?

  1. Maintaining a specified number of matching Pods
  2. Storing passwords
  3. Exposing HTTP routes
  4. Creating namespaces

Answer: A) Maintaining a specified number of matching Pods

Explanation: A ReplicaSet maintains a stable number of running Pods that match its selector and Pod template.

7. Which Kubernetes resource normally manages ReplicaSets during application rollouts?

  1. Deployment
  2. Service
  3. ConfigMap
  4. Namespace

Answer: A) Deployment

Explanation: A Deployment manages ReplicaSets and provides declarative updates, including controlled replacement of Pods during application revisions.

8. What is the main purpose of a Kubernetes Service?

  1. Provide a stable network endpoint for a set of Pods
  2. Store container images
  3. Schedule Pods onto nodes
  4. Store sensitive credentials

Answer: A) Provide a stable network endpoint for a set of Pods

Explanation: Pods can be created and replaced dynamically, so a Service provides a stable abstraction for accessing a group of Pods selected by labels.

9. Which Kubernetes Service type is commonly used to expose a Service externally through a cloud provider's load balancer?

  1. LoadBalancer
  2. ClusterIP
  3. ExternalName
  4. Headless

Answer: A) LoadBalancer

Explanation: A Service of type LoadBalancer can provision or integrate with an external load balancer when supported by the underlying environment.

10. What is the default Service type in Kubernetes?

  1. ClusterIP
  2. LoadBalancer
  3. NodePort
  4. ExternalName

Answer: A) ClusterIP

Explanation: ClusterIP provides a Service reachable within the cluster and is the default Service type.

11. What does a NodePort Service provide?

  1. Exposure of a Service through a port on each node
  2. Persistent storage for Pods
  3. Automatic database replication
  4. A private container registry

Answer: A) Exposure of a Service through a port on each node

Explanation: NodePort exposes a Service on a statically allocated port on each node, subject to the cluster's networking implementation.

12. What is a ConfigMap used for?

  1. Storing non-confidential configuration data
  2. Storing encrypted container images
  3. Managing cluster nodes
  4. Creating persistent disks

Answer: A) Storing non-confidential configuration data

Explanation: ConfigMaps store non-confidential key-value configuration data and can be consumed by Pods as environment variables, command-line arguments, or files.

13. Which Kubernetes object is intended for confidential data such as passwords and tokens?

  1. Secret
  2. ConfigMap
  3. Deployment
  4. Service

Answer: A) Secret

Explanation: Kubernetes Secrets are intended to hold confidential data such as passwords, tokens, and keys.

14. What is a StatefulSet designed to manage?

  1. Stateful applications whose Pods require stable identities or persistent storage
  2. Only stateless web servers
  3. Container image registries
  4. Cluster-wide network policies

Answer: A) Stateful applications whose Pods require stable identities or persistent storage

Explanation: StatefulSets are designed for workloads where Pods need stable identities and often persistent storage.

15. What is a key characteristic of Pods managed by a StatefulSet?

  1. They can have stable, predictable identities
  2. They always share the same IP address
  3. They cannot use persistent storage
  4. They are automatically deleted after every request

Answer: A) They can have stable, predictable identities

Explanation: StatefulSet Pods have ordinal identities and can be associated with persistent storage, making them suitable for stateful workloads.

16. What is a DaemonSet used for?

  1. Running a Pod on each eligible node or a selected set of nodes
  2. Running a single Pod once
  3. Storing application secrets
  4. Managing only external DNS records

Answer: A) Running a Pod on each eligible node or a selected set of nodes

Explanation: A DaemonSet ensures that a Pod runs on nodes matching its scheduling criteria. It is commonly used for node-level services such as logging or monitoring agents.

17. What is a Kubernetes Job?

  1. A workload that runs Pods to completion
  2. A long-running Service endpoint
  3. A network policy
  4. A storage class

Answer: A) A workload that runs Pods to completion

Explanation: A Job creates Pods that perform a task and tracks successful completion. It is intended for tasks that run to completion rather than continuously serving traffic.

18. What is a CronJob used for?

  1. Running Jobs repeatedly according to a schedule
  2. Exposing a Service through HTTP
  3. Managing persistent volumes
  4. Assigning Pods to nodes manually

Answer: A) Running Jobs repeatedly according to a schedule

Explanation: A CronJob creates Jobs on a repeating schedule, making it suitable for tasks such as scheduled reports and backups.

19. What is the purpose of the Kubernetes control plane?

  1. Manage the desired state and coordinate the cluster
  2. Only run application containers
  3. Store user passwords in application Pods
  4. Provide physical network cables

Answer: A) Manage the desired state and coordinate the cluster

Explanation: Control-plane components expose the Kubernetes API and coordinate cluster state, scheduling, and controller operations.

20. Which Kubernetes component serves as the primary API entry point for the cluster?

  1. kube-apiserver
  2. kubelet
  3. kube-proxy
  4. CoreDNS

Answer: A) kube-apiserver

Explanation: The kube-apiserver exposes the Kubernetes HTTP API and serves as the front end of the Kubernetes control plane.

21. What is the role of the kubelet?

  1. Ensure containers described by Pod specifications are running on a node
  2. Store cluster configuration in a database
  3. Act as the Kubernetes API server
  4. Provide DNS records for external websites

Answer: A) Ensure containers described by Pod specifications are running on a node

Explanation: The kubelet runs on each node and works with the container runtime to ensure that containers associated with Pods are running and healthy according to their specifications.

22. What is kube-proxy primarily associated with?

  1. Implementing part of the Service networking behavior on nodes
  2. Scheduling Pods
  3. Storing Secrets
  4. Managing container images

Answer: A) Implementing part of the Service networking behavior on nodes

Explanation: kube-proxy is a network proxy that runs on nodes and helps implement part of the Kubernetes Service abstraction, depending on the cluster's networking configuration.

23. What is etcd in Kubernetes?

  1. A distributed key-value store used to persist Kubernetes cluster state
  2. A container runtime
  3. A Pod scheduler
  4. A network load balancer

Answer: A) A distributed key-value store used to persist Kubernetes cluster state

Explanation: etcd stores Kubernetes API data and cluster state. Protecting etcd is therefore important for cluster security and availability.

24. What is the Kubernetes scheduler responsible for?

  1. Selecting suitable nodes for Pods that need scheduling
  2. Creating container images
  3. Storing Secrets
  4. Serving application HTTP traffic

Answer: A) Selecting suitable nodes for Pods that need scheduling

Explanation: The scheduler evaluates unscheduled Pods and selects nodes that satisfy their scheduling requirements and constraints.

25. What is a namespace in Kubernetes?

  1. A mechanism for isolating groups of namespaced resources within a cluster
  2. A physical worker node
  3. A container image format
  4. A network cable

Answer: A) A mechanism for isolating groups of namespaced resources within a cluster

Explanation: Namespaces provide a scope for names and can help divide cluster resources between teams or projects. Not all Kubernetes resources are namespaced.

26. Which resource is cluster-scoped rather than namespaced?

  1. Node
  2. Pod
  3. Deployment
  4. Service

Answer: A) Node

Explanation: Nodes are cluster-scoped resources, whereas Pods, Deployments, and Services are namespaced resources. PersistentVolumes and StorageClasses are also cluster-scoped.

27. What is a label in Kubernetes?

  1. A key-value pair attached to an object for identification and selection
  2. A password used for API authentication
  3. A container image layer
  4. A network port

Answer: A) A key-value pair attached to an object for identification and selection

Explanation: Labels organize Kubernetes objects and allow selectors to identify groups of resources, such as the Pods targeted by a Service.

28. What is a label selector used for?

  1. Selecting Kubernetes objects based on their labels
  2. Encrypting Secrets
  3. Creating container images
  4. Assigning IP addresses manually

Answer: A) Selecting Kubernetes objects based on their labels

Explanation: Selectors are used by resources such as Services and controllers to identify the objects they should operate on.

29. What is a PersistentVolume (PV)?

  1. A cluster storage resource that can provide persistent storage to workloads
  2. A temporary container filesystem
  3. A network Service
  4. A Pod scheduling rule

Answer: A) A cluster storage resource that can provide persistent storage to workloads

Explanation: A PersistentVolume represents storage provisioned for use by Kubernetes workloads independently of the lifecycle of an individual Pod.

30. What is a PersistentVolumeClaim (PVC)?

  1. A request for storage by a workload
  2. A request to create a new Kubernetes node
  3. A request for an external IP address
  4. A request to create a ServiceAccount

Answer: A) A request for storage by a workload

Explanation: A PVC requests storage with specified requirements such as capacity and access modes, and Kubernetes can bind it to a suitable PersistentVolume.

31. What is a StorageClass used for?

  1. Defining classes of dynamically provisioned storage
  2. Defining container CPU limits
  3. Creating Pods automatically
  4. Managing user passwords

Answer: A) Defining classes of dynamically provisioned storage

Explanation: A StorageClass describes different storage classes and can enable dynamic provisioning of PersistentVolumes through an appropriate provisioner.

32. What is a liveness probe used for?

  1. Determining whether a container should be restarted because it is unhealthy
  2. Determining whether a Pod should receive traffic
  3. Creating a PersistentVolume
  4. Authenticating a user

Answer: A) Determining whether a container should be restarted because it is unhealthy

Explanation: A failed liveness probe can cause the kubelet to restart the affected container according to the Pod's restart policy.

33. What is a readiness probe used for?

  1. Determining whether a container is ready to receive traffic
  2. Restarting every container at startup
  3. Creating a Service
  4. Assigning a node to a Pod

Answer: A) Determining whether a container is ready to receive traffic

Explanation: When a readiness probe fails, Kubernetes marks the container as not ready and matching Services stop sending traffic to the Pod.

34. What is a startup probe useful for?

  1. Allowing a slow-starting application time to initialize before liveness or readiness checks take effect
  2. Creating a new cluster
  3. Assigning RBAC permissions
  4. Creating a PersistentVolume

Answer: A) Allowing a slow-starting application time to initialize before liveness or readiness checks take effect

Explanation: When configured, a startup probe is used to determine whether an application has started. Kubernetes does not execute liveness or readiness probes until the startup probe succeeds.

35. What is a Horizontal Pod Autoscaler (HPA) used for?

  1. Automatically adjusting the number of workload Pods based on observed metrics
  2. Increasing the physical size of nodes
  3. Changing container images
  4. Creating namespaces

Answer: A) Automatically adjusting the number of workload Pods based on observed metrics

Explanation: HPA can change the replica count of supported workloads based on resource utilization or other configured metrics.

36. What is a resource request in a Kubernetes container specification?

  1. The amount of a resource that Kubernetes uses when making scheduling decisions
  2. The maximum number of nodes in a cluster
  3. The number of replicas in a Deployment
  4. The external IP address of a Service

Answer: A) The amount of a resource that Kubernetes uses when making scheduling decisions

Explanation: Resource requests specify the amount of CPU, memory, or other supported resources a container expects to require and are considered by the scheduler.

37. What is a resource limit?

  1. A maximum amount of a resource that a container is allowed to consume
  2. A minimum number of Pods required in a Deployment
  3. A maximum number of namespaces in a cluster
  4. A fixed Service IP address

Answer: A) A maximum amount of a resource that a container is allowed to consume

Explanation: Resource limits define maximum resource consumption for containers, such as CPU and memory, subject to Kubernetes and runtime behavior.

38. What is RBAC in Kubernetes?

  1. Role-Based Access Control
  2. Resource-Based Application Cache
  3. Runtime Backup and Control
  4. Replica-Based Access Configuration

Answer: A) Role-Based Access Control

Explanation: Kubernetes RBAC controls access to API resources by assigning permissions through Roles, ClusterRoles, RoleBindings, and ClusterRoleBindings.

39. What is the difference between a Role and a ClusterRole?

  1. A Role is namespaced, while a ClusterRole can define permissions at cluster scope
  2. A Role manages Pods while a ClusterRole manages containers
  3. A Role is only for users while a ClusterRole is only for Pods
  4. There is no difference

Answer: A) A Role is namespaced, while a ClusterRole can define permissions at cluster scope

Explanation: A Role defines permissions within a namespace. A ClusterRole can define permissions for cluster-scoped resources or be used to grant permissions across namespaces through appropriate bindings.

40. What is a ServiceAccount used for?

  1. Providing an identity for workloads and other automated processes
  2. Storing application configuration
  3. Creating container images
  4. Replacing a Kubernetes node

Answer: A) Providing an identity for workloads and other automated processes

Explanation: ServiceAccounts provide identities that Pods and other automated processes can use when communicating with the Kubernetes API or external services.

41. What principle should be followed when granting RBAC permissions to a ServiceAccount?

  1. Least privilege
  2. Maximum privilege
  3. Anonymous privilege
  4. Universal administrator access

Answer: A) Least privilege

Explanation: ServiceAccounts should receive only the permissions required for their workloads. Kubernetes documentation specifically recommends using RBAC to grant the minimum required permissions.

42. What is a NetworkPolicy used for?

  1. Controlling allowed network traffic to and from selected Pods
  2. Creating container images
  3. Managing persistent disks
  4. Scheduling Pods on nodes

Answer: A) Controlling allowed network traffic to and from selected Pods

Explanation: NetworkPolicy describes which network traffic is allowed for selected Pods, providing a mechanism for network segmentation when supported by the cluster network implementation.

43. What is an Ingress resource commonly used for?

  1. Routing external HTTP or HTTPS traffic to Services
  2. Storing container passwords
  3. Scheduling Pods
  4. Managing PersistentVolumes

Answer: A) Routing external HTTP or HTTPS traffic to Services

Explanation: Ingress defines rules for exposing HTTP and HTTPS routes from outside the cluster to Services. Kubernetes currently recommends Gateway instead for new development because the Ingress API is frozen.

44. Which Kubernetes API resource is recommended by the project as the successor direction for new traffic-management development instead of Ingress?

  1. Gateway
  2. ConfigMap
  3. ReplicaSet
  4. PersistentVolume

Answer: A) Gateway

Explanation: Kubernetes documents the Ingress API as frozen and recommends Gateway for new development in this area.

45. What does a rolling update of a Deployment generally accomplish?

  1. Gradually replaces old Pods with new Pods
  2. Deletes all Pods before creating any replacement
  3. Changes the cluster's physical nodes
  4. Converts a Deployment into a StatefulSet

Answer: A) Gradually replaces old Pods with new Pods

Explanation: A Deployment can update its Pods progressively, allowing a new version to be introduced while controlling how many old and new Pods are available during the rollout.

46. What does a Kubernetes selector in a Service commonly identify?

  1. The Pods that should receive traffic from the Service
  2. The node that runs the API server
  3. The Secret containing a password
  4. The container image registry

Answer: A) The Pods that should receive traffic from the Service

Explanation: A Service can use a label selector to identify the set of Pods that provide its backend endpoints.

47. A Deployment has three replicas, but one Pod crashes. What is the expected behavior of the Deployment's managed workload?

  1. Kubernetes works to restore the desired number of available Pods
  2. The Deployment is permanently deleted
  3. The Service is automatically converted to a StatefulSet
  4. The namespace is deleted

Answer: A) Kubernetes works to restore the desired number of available Pods

Explanation: Deployments manage ReplicaSets, which maintain the desired number of Pods. If a managed Pod fails, the controller works to create a replacement as necessary.

48. A Kubernetes application stores database data in the container's writable filesystem. What is the primary concern if the Pod is replaced?

  1. The data may not persist across the Pod lifecycle
  2. The Service automatically becomes unavailable forever
  3. The namespace is deleted
  4. The Deployment loses all RBAC roles

Answer: A) The data may not persist across the Pod lifecycle

Explanation: A container's writable filesystem is tied to the container lifecycle. Stateful applications generally require persistent storage, often through PersistentVolumes and PersistentVolumeClaims.

49. A Kubernetes CronJob performs a database backup every night. Why should the backup operation ideally be idempotent?

  1. Because certain scheduling situations can result in more than one Job being created for a schedule
  2. Because CronJobs never create Jobs
  3. Because Kubernetes deletes every backup immediately
  4. Because a CronJob can only execute once

Answer: A) Because certain scheduling situations can result in more than one Job being created for a schedule

Explanation: Kubernetes documents that CronJobs can have scheduling limitations and, in certain circumstances, may create multiple concurrent Jobs. Therefore, Jobs created by CronJobs should be designed to be idempotent where possible.

50. A production Kubernetes cluster runs a web application with multiple replicas, private configuration, persistent data, and restricted internal communication. Which combination best addresses these requirements?

  1. Deployment, Service, ConfigMap/Secret, PersistentVolumeClaim, readiness and liveness probes, RBAC, and NetworkPolicy
  2. Only a single Pod with all configuration hard-coded into the image
  3. Only a ConfigMap and no Service or workload controller
  4. A single container with administrator privileges and no health checks

Answer: A) Deployment, Service, ConfigMap/Secret, PersistentVolumeClaim, readiness and liveness probes, RBAC, and NetworkPolicy

Explanation: A Deployment manages replicated application Pods, a Service provides stable networking, ConfigMaps and Secrets separate configuration from application code, a PersistentVolumeClaim provides persistent storage, probes support health and traffic management, RBAC controls API permissions, and NetworkPolicy can restrict network communication. These components address different operational and security requirements rather than attempting to solve everything with a single Kubernetes resource.

Comments and Discussions!

Load comments ↻



Copyright © 2026 www.includehelp.com. All rights reserved.