CKA Practice Question: Cluster Architecture, Installation and Configuration
What is the default port for the Kubernetes API server?
⚠ Common exam trap
Many exam-takers confuse the deprecated insecure port 8080 with the default secure port 6443, especially if they have experience with older Kubernetes versions or minikube setups that might expose port 8080 locally.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
6443
The Kubernetes API server defaults to port 6443 for secure HTTPS traffic. This is the standard port used by kubectl and other clients to communicate with the control plane over TLS-encrypted connections, as defined in the Kubernetes documentation and default kube-apiserver configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
10250
Why it's wrong here
Port 10250 is the kubelet's own HTTPS endpoint, used for node-level operations such as pod logs, exec, and port-forwarding, as well as the kubelet's health checks. The kube-apiserver does not listen on this port; instead, the API server selectively connects to each node's kubelet on 10250 when a user requests pod logs or exec. Therefore, choosing 10250 confuses the Kubernetes data-plane endpoint with the control-plane API server's secure listener.
- ✗
8080
Why it's wrong here
Port 8080 refers to the legacy insecure HTTP port that kube-apiserver could listen on in older versions prior to Kubernetes 1.6 when explicitly started with --insecure-port=8080. This port is disabled by default in modern Kubernetes because it exposes the API without authentication, and the default secure HTTPS endpoint is 6443. The existence of an insecure port never made 8080 the default; it was always an optional, deprecated listener.
- ✗
2379
Why it's wrong here
Port 2379 is the client-facing endpoint of etcd, the Kubernetes backing store, where kube-apiserver connects to read and write all cluster state. While the API server relies heavily on this port for persistence, it is not the port that clients, kubectl, or controllers use to talk to the API server. The control plane's API server itself is served externally on 6443, making 2379 an internal storage port rather than a user API port.
- ✓
6443
Why this is correct
Kubernetes API server listens on TCP port 6443 by default for secure HTTPS traffic, which is the endpoint encoded in kubeconfig files and used by kubectl, controllers, and external clients. This port is enabled by default, uses TLS for encrypted communication, and can be overridden with the --secure-port flag on kube-apiserver. All core API requests, including authentication and RBAC enforcement, pass through this secure listener.
Go deeper
Related to this question
Learn chapter
Installing Kubernetes with kubeadm
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
kubectl Command Reference
kubectl is the command-line tool used to interact with and manage Kubernetes clusters by sending commands to the Kubernetes API.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.