Courseiva

CKA Practice Question: Cluster Architecture, Installation and Configuration

Which component is responsible for maintaining network rules on each worker node to enable service discovery and load balancing?

⚠ Common exam trap

Test-takers frequently confuse the responsibility for DNS-based service discovery (CoreDNS) with the responsibility for network-level traffic routing and load balancing (kube-proxy), leading candidates to incorrectly select CoreDNS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kube-proxy

kube-proxy is the component responsible for maintaining network rules on each worker node. It implements the Kubernetes Service concept by managing IP tables or IPVS rules to route traffic to the correct Pods, enabling service discovery and load balancing across Pod endpoints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kube-controller-manager

    Why it's wrong here

    The kube-controller-manager is a control plane component that runs core controller loops to regulate the state of the cluster, such as the Node, Deployment, and Namespace controllers. It does not interact with host-level networking or configure packet-filtering rules like iptables or IPVS to route Service traffic.

  • ✗

    CoreDNS

    Why it's wrong here

    CoreDNS is a flexible, extensible DNS server that runs as a deployment inside the cluster to provide name resolution and service discovery for Pods. While it resolves Service names to ClusterIPs, it does not manipulate the underlying routing tables or packet-filtering rules on individual cluster nodes.

  • ✓

    kube-proxy

    Why this is correct

    kube-proxy is the network agent running on each node that implements the Kubernetes Service abstraction. It watches the API server for changes to Service and EndpointSlice objects, translating them into local OS-level network rules using backends like iptables, IPVS, or eBPF to forward traffic to the correct backend Pods.

  • ✗

    kubelet

    Why it's wrong here

    The kubelet is the primary node agent responsible for ensuring that containers described in PodSpecs are running and healthy on its host. While it interacts with Container Runtime Interface (CRI) and Container Network Interface (CNI) plugins to set up Pod network namespaces, it does not manage the cluster-wide Service routing rules.

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.