Courseiva
Services and Networking →easyMultiple Choice

CKA Services and Networking Practice Question

Which kube-proxy mode supports connection-based load balancing using Linux IPVS?

⚠ Common exam trap

A common misconception is that 'iptables' is the only or best mode for connection-based load balancing, but iptables does not natively support connection-based persistence without relying on conntrack, while IPVS explicitly provides it through its scheduling algorithms and connection table.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ipvs

The IPVS (IP Virtual Server) mode in kube-proxy uses the Linux kernel's IPVS module to implement Layer 4 (transport layer) load balancing. IPVS supports multiple scheduling algorithms (e.g., round-robin, least connections) and provides connection-based load balancing by maintaining a connection tracking table, which allows it to forward packets belonging to the same TCP/UDP session to the same backend pod. This is more efficient than iptables for large-scale clusters due to its use of hash tables (O(1) lookup) rather than linear rule chains.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ipvs

    Why this is correct

    IPVS (IP Virtual Server) in kube-proxy runs in kernel space and supports advanced scheduling algorithms such as least-connections, source hashing, and weighted round-robin. It maintains per-connection state in a connection table, allowing it to route new connections to backends with the fewest active connections and thereby implement true connection-based load balancing. This goes beyond simple random or round-robin selection.

  • ✗

    iptables

    Why it's wrong here

    iptables mode works by installing NAT chains with `--probability` rules that effectively perform random selection among backend pods for each new connection. It does not track connection counts, backend load, or session state, so it cannot make load-aware routing decisions. As a result, it implements a statistically even but effectively random distribution, not connection-based load balancing.

  • ✗

    kernelspace

    Why it's wrong here

    kernelspace is not a valid kube-proxy mode; the officially supported modes are userspace, iptables, and ipvs. Some may confuse it with ipvs (which is kernel-based) or with the deprecated userspace proxy, but no such mode exists. Therefore, it cannot provide any load balancing functionality at all, and selecting it would be invalid.

  • ✗

    userspace

    Why it's wrong here

    The legacy userspace mode ran a user-space proxy process that listened on the service IP and performed simple round-robin forwarding to backend pods. It did not consult connection counts or server health, so its load balancing was purely static and even, not connection-based. Due to high overhead from copying packets between user and kernel space, it was deprecated in favor of iptables and ipvs.

About these practice questions

Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.