CKA Practice Question: Cluster Architecture, Installation and Configuration
What is the purpose of the kube-proxy component in a Kubernetes cluster?
⚠ Common exam trap
Many candidates confuse kube-proxy with the kubelet or kube-scheduler because all three are node-level components, but kube-proxy's sole purpose is network proxying and Service load balancing, not pod management or scheduling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It provides network proxy and load balancing for services
Kube-proxy is the component responsible for implementing the Kubernetes Service concept by maintaining network rules on each node. It performs connection forwarding and load balancing for Service endpoints using either iptables, IPVS, or userspace mode, ensuring that traffic destined for a Service's ClusterIP is correctly routed to healthy Pods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It provides network proxy and load balancing for services
Why this is correct
kube-proxy watches the Kubernetes API for Services and EndpointSlices, then programs node-level iptables or IPVS rules so that traffic to a Service's ClusterIP is DNATed to healthy backend Pod IPs. This distributed, kernel-mode forwarding is what makes Service load balancing work without a centralized proxy.
- ✗
It schedules pods to nodes
Why it's wrong here
Pod scheduling is performed by the kube-scheduler, a control-plane component that evaluates resource requests, node affinity, taints, and tolerations to pick a suitable node. kube-proxy runs on every node but has no role in node selection or placement decisions.
- ✗
It manages the lifecycle of pods
Why it's wrong here
Pod lifecycle management is the kubelet's responsibility: the node agent pulls container images, starts/exits containers, performs liveness/readiness probes, and restarts failing containers. kube-proxy only manipulates network rules (iptables/IPVS) and never interacts with the container runtime or pod lifecycle hooks.
- ✗
It stores cluster configuration data
Why it's wrong here
Cluster configuration and all persistent state are stored in etcd, a distributed key-value store. kube-proxy does not persist any data — it merely watches Services/Endpoints and writes ephemeral kernel routing rules on each node, which disappear when the daemon is restarted.
Go deeper
Related to this question
Learn chapter
Network Policies and Secure Connectivity
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
ClusterIP NodePort LoadBalancer
ClusterIP, NodePort, and LoadBalancer are three types of Kubernetes Services that control how traffic reaches your application pods inside the cluster or from outside.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.