CKA Practice Question: Cluster Architecture, Installation and Configuration
Which component is responsible for maintaining network rules on each worker node to enable service discovery and load balancing?
⚠ Common exam trap
Test-takers frequently confuse the responsibility for DNS-based service discovery (CoreDNS) with the responsibility for network-level traffic routing and load balancing (kube-proxy), leading candidates to incorrectly select CoreDNS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kube-proxy
kube-proxy is the component responsible for maintaining network rules on each worker node. It implements the Kubernetes Service concept by managing IP tables or IPVS rules to route traffic to the correct Pods, enabling service discovery and load balancing across Pod endpoints.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kube-controller-manager
Why it's wrong here
The kube-controller-manager is a control plane component that runs core controller loops to regulate the state of the cluster, such as the Node, Deployment, and Namespace controllers. It does not interact with host-level networking or configure packet-filtering rules like iptables or IPVS to route Service traffic.
- ✗
CoreDNS
Why it's wrong here
CoreDNS is a flexible, extensible DNS server that runs as a deployment inside the cluster to provide name resolution and service discovery for Pods. While it resolves Service names to ClusterIPs, it does not manipulate the underlying routing tables or packet-filtering rules on individual cluster nodes.
- ✓
kube-proxy
Why this is correct
kube-proxy is the network agent running on each node that implements the Kubernetes Service abstraction. It watches the API server for changes to Service and EndpointSlice objects, translating them into local OS-level network rules using backends like iptables, IPVS, or eBPF to forward traffic to the correct backend Pods.
- ✗
kubelet
Why it's wrong here
The kubelet is the primary node agent responsible for ensuring that containers described in PodSpecs are running and healthy on its host. While it interacts with Container Runtime Interface (CRI) and Container Network Interface (CNI) plugins to set up Pod network namespaces, it does not manage the cluster-wide Service routing rules.
Go deeper
Related to this question
Learn chapter
Managing Cluster Upgrades
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
Kubernetes Node Roles
Kubernetes Node Roles are labels assigned to machines in a cluster that define whether a node runs application containers (worker) or manages the cluster (control plane).
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.