Question 1
Which is a use case for combining Init Containers with Persistent Volume Claims (PVCs)?
Correct Answer:
To initialize a database schema before the app starts
Explanation:
Init containers run to completion before the main application containers, and when they mount the same persistent volume, they can set up the data that the app will use. This makes it ideal to pre-create and populate a database’s schema or seed data in a volume before the application starts. By initializing the data directory on the PVC, the app container starts with a ready-to-use database, avoiding migrations or setup at first run and reducing startup failures. For example, a PVC backs the database data directory; an Init Container runs the schema creation and seeds, writes the initial state to the mounted path, and only then does the main app container start using that pre-initialized data. Other patterns like sidecar logging, health checks, or secret management serve different purposes and don’t specifically involve preparing a persistent data store before startup.
Question 2
In Kubernetes, how do you request and attach persistent storage to a Pod?
Correct Answer:
By defining a PersistentVolumeClaim in the Pod specification
Explanation:
In Kubernetes, to request and attach persistent storage to a Pod you use a PersistentVolumeClaim and connect it to the Pod through a volume. The claim specifies how much storage you need and with what access mode, and Kubernetes will bind it to an existing PersistentVolume or dynamically provision one if a StorageClass is configured. In the Pod spec you then declare a volume that uses that claim (persistentVolumeClaim: claimName: your-pvc) and mount it into the container via a volumeMounts entry. This approach decouples the Pod from the storage lifecycle and enables portability and dynamic provisioning. ConfigMaps are for configuration data, not storage. A StorageClass defines how storage is provisioned but isn’t directly attached to a Pod; it’s used by the PVC to provision PVs. Mounting a hostPath attaches a directory from the node’s filesystem, which isn’t portable or durable across nodes.
Question 3
Which tool exposes metrics describing the state of Kubernetes objects, such as pods and deployments, for monitoring?
Correct Answer:
Kube-state-metrics
Explanation:
The thing being tested is how you get metrics that describe the real-time state of Kubernetes objects. The tool that does this is kube-state-metrics. It runs in the cluster, queries the Kubernetes API for resources like pods and deployments, and exposes metrics in Prometheus format. This lets Prometheus scrape data such as pod status, deployment replicas, and ready counts to monitor how resources are actually behaving. Prometheus is the scraping and storage system, not the source of the object-state metrics. CoreDNS handles DNS inside the cluster, not object-state monitoring. Kubelet runs on each node and exposes node-level and container metrics, not a broad view of Kubernetes object states.
Question 4
In Kubernetes, which security-focused tool is commonly used for runtime security monitoring and detection of anomalous activities within containers and pods?
Correct Answer:
Falco
Explanation:
Focusing on runtime behavior inside containers and pods, this question centers on real-time security monitoring that detects anomalous activities as workloads run. Falco is designed for exactly that: a runtime security tool that watches what the system is actually doing, rather than just scanning configurations or images. Falco observes kernel and system call events from the host (and can be deployed in Kubernetes as a DaemonSet) and uses a flexible rules engine to flag suspicious activity. This lets you detect things like a shell being spawned inside a running container, a container accessing sensitive host paths, unusual process trees, or unexpected network connections from a pod. Because it analyzes behavior in real time, it provides immediate alerts about active threats or policy violations, which is essential for protecting workloads in a dynamic Kubernetes environment. Other options offer valuable security capabilities, like image scanning, secrets protection, or broader runtime protection suites, but Falco’s strength lies in its focused, open-source, runtime, rule-based detection tailored to Kubernetes workloads.
Question 5
What is a sidecar container?
Correct Answer:
A container that runs alongside the main container to handle administrative tasks
Explanation:
A sidecar container is a companion container that runs in the same Kubernetes Pod as the main application container and performs supporting tasks. It handles auxiliary work like log collection, monitoring, data synchronization, or proxying requests, so the primary process can stay focused on its core function. Because it shares the Pod’s network space and can mount the same volumes, the sidecar and the main container can communicate directly (often via localhost) and coordinate through the shared filesystem. This pattern keeps operational concerns separate from the main application logic without needing a separate Pod. For example, a logging agent or a token refresher running as a sidecar can handle those tasks transparently while the main app processes data.
Question 1
Exam overview

About this Exam

Prepare with the Kubernetes Certified Network Administrator (KCNA) Part 2 Practice Test practice quiz. This question bank includes 10 questions covering kubernetes, persistent, containers, storage, and tool. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

Kubernetes Certified Network Administrator (KCNA) Part 2 Practice Test

This practice set contains 10 questions from the matching question bank and focuses on kubernetes, persistent, containers, storage, and tool. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions