Courseiva

CKA Practice Question: Cluster Architecture, Installation and Configuration

Which component is responsible for managing the network rules and forwarding on each node?

⚠ Common exam trap

CNCF often tests the misconception that kubelet handles networking, but kubelet only manages pod lifecycle and container runtime interactions, not network rule management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kube-proxy

kube-proxy is the component responsible for managing network rules and forwarding traffic on each node. It implements the Kubernetes Service concept by maintaining iptables or IPVS rules that route packets to the correct backend pods, handling load balancing and service discovery at the network layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    container runtime

    Why it's wrong here

    The container runtime (for example, containerd or CRI-O) is responsible for executing containers, managing image pulls, and enforcing cgroups and namespaces for isolation. While it may invoke CNI plugins to give a Pod a network interface, it does not program the cluster network rules for Services. Those forwarding rules—such as iptables or IPVS rules for ClusterIP—are installed by kube-proxy, not by the container runtime.

  • ✗

    kubelet

    Why it's wrong here

    The kubelet is the node agent that communicates with the control plane to ensure Pods are running; it starts or restarts containers, mounts volumes, and reports node and pod status. As part of pod synchronization it can prepare the pod's network namespace at the node level, but it does not maintain Service-level network rules. When a Service is created, kube-proxy reacts to API changes and creates the connection-forwarding rules, while the kubelet only supervises the local pod lifecycle.

  • ✓

    kube-proxy

    Why this is correct

    kube-proxy runs as a DaemonSet on every node and watches the Kubernetes API server for updates to Service and EndpointSlice objects. It is the component that manages network rules for Services by writing entries into iptables or IPVS, which then perform DNAT, load balancing, and connection forwarding to backend Pods. Without kube-proxy, or an equivalent replacement, ClusterIP and NodePort Services would not have the kernel rules necessary to route Service traffic.

  • ✗

    kube-scheduler

    Why it's wrong here

    The kube-scheduler is a control-plane component that selects a node for a newly created Pod based on resource requirements, taints and tolerations, and affinity or anti-affinity constraints. Once it chooses, it creates a Binding object so the kubelet can start the Pod. It never inspects network policies or Service rules, nor does it modify iptables or IPVS; its sole concern is placement, so it cannot be responsible for managing network rules.

About these practice questions

This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.