Courseiva

CKA Practice Question: Cluster Architecture, Installation and Configuration

What is the default port for the Kubernetes API server?

⚠ Common exam trap

Many exam-takers confuse the deprecated insecure port 8080 with the default secure port 6443, especially if they have experience with older Kubernetes versions or minikube setups that might expose port 8080 locally.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

6443

The Kubernetes API server defaults to port 6443 for secure HTTPS traffic. This is the standard port used by kubectl and other clients to communicate with the control plane over TLS-encrypted connections, as defined in the Kubernetes documentation and default kube-apiserver configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    10250

    Why it's wrong here

    Port 10250 is the kubelet's own HTTPS endpoint, used for node-level operations such as pod logs, exec, and port-forwarding, as well as the kubelet's health checks. The kube-apiserver does not listen on this port; instead, the API server selectively connects to each node's kubelet on 10250 when a user requests pod logs or exec. Therefore, choosing 10250 confuses the Kubernetes data-plane endpoint with the control-plane API server's secure listener.

  • ✗

    8080

    Why it's wrong here

    Port 8080 refers to the legacy insecure HTTP port that kube-apiserver could listen on in older versions prior to Kubernetes 1.6 when explicitly started with --insecure-port=8080. This port is disabled by default in modern Kubernetes because it exposes the API without authentication, and the default secure HTTPS endpoint is 6443. The existence of an insecure port never made 8080 the default; it was always an optional, deprecated listener.

  • ✗

    2379

    Why it's wrong here

    Port 2379 is the client-facing endpoint of etcd, the Kubernetes backing store, where kube-apiserver connects to read and write all cluster state. While the API server relies heavily on this port for persistence, it is not the port that clients, kubectl, or controllers use to talk to the API server. The control plane's API server itself is served externally on 6443, making 2379 an internal storage port rather than a user API port.

  • ✓

    6443

    Why this is correct

    Kubernetes API server listens on TCP port 6443 by default for secure HTTPS traffic, which is the endpoint encoded in kubeconfig files and used by kubectl, controllers, and external clients. This port is enabled by default, uses TLS for encrypted communication, and can be overridden with the --secure-port flag on kube-apiserver. All core API requests, including authentication and RBAC enforcement, pass through this secure listener.

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.