CKA Services and Networking Practice Question
A cluster has kube-proxy running in ipvs mode. An administrator creates a Service of type ClusterIP. Which of the following is true about how traffic is forwarded to the pods?
⚠ Common exam trap
Many exam-takers confuse kube-proxy modes (userspace, iptables, ipvs) and assume iptables rules are always used, or mistakenly think DNS handles load balancing, when in fact ipvs mode uses kernel-level virtual servers with explicit scheduling algorithms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kube-proxy creates IPVS virtual servers that use scheduling algorithms like round-robin
When kube-proxy runs in ipvs mode, it creates IPVS virtual servers for each ClusterIP Service. These virtual servers use kernel-level scheduling algorithms (e.g., round-robin, least connections) to forward traffic directly to the selected backend pods, bypassing iptables for per-packet decisions. This provides better performance and more sophisticated load-balancing policies compared to iptables mode.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kube-proxy uses userspace mode to proxy traffic
Why it's wrong here
In userspace mode, kube-proxy watches the Kubernetes master for Service and Endpoint changes, then opens a random port on the local node to proxy traffic from the virtual IP to the backend pods. This is an obsolete, highly inefficient legacy mode that incurs significant context-switching overhead between user space and kernel space. It is entirely distinct from the high-performance IPVS mode, which operates directly in kernel space.
- ✗
kube-proxy uses iptables rules to randomly select a pod
Why it's wrong here
This describes the default iptables mode, where kube-proxy programs sequential iptables chains and uses the statistic module to randomly distribute traffic across backend pods. In contrast, IPVS mode bypasses these complex, O(N) sequential iptables rule evaluations by utilizing IPVS virtual servers and hash tables. This allows IPVS to scale efficiently to thousands of services without degrading packet processing performance.
- ✗
kube-proxy does nothing; the cluster DNS does the load balancing
Why it's wrong here
CoreDNS or kube-dns only resolves Service names to their corresponding ClusterIPs or headless pod IPs; it does not perform active layer-4 load balancing or traffic proxying. Once the client resolves the IP address, kube-proxy (configured in IPVS mode) intercepts the traffic directed to the ClusterIP and routes it to the appropriate backend pod. Relying solely on DNS for load balancing would fail due to client-side caching and lack of health-checking mechanisms.
- ✓
kube-proxy creates IPVS virtual servers that use scheduling algorithms like round-robin
Why this is correct
When configured in IPVS mode, kube-proxy implements Netfilter hooks and programs IPVS virtual servers to handle Service traffic directly in kernel space. This mode supports sophisticated load-balancing algorithms such as round-robin (rr), least connection (lc), destination hashing (dh), and source hashing (sh). This architecture provides superior throughput and lower latency compared to iptables, especially in large-scale clusters with thousands of Services.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.