CKA Services and Networking Practice Question
Which kube-proxy mode uses iptables rules to handle service traffic and is the default in many distributions?
⚠ Common exam trap
Many candidates confuse the default kube-proxy mode with the ipvs mode, which is more performant but requires explicit configuration, or mistakenly think nftables is a supported mode in current Kubernetes releases.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
iptables
The iptables mode is the default kube-proxy mode in many Kubernetes distributions, including kubeadm-based clusters. In this mode, kube-proxy watches the Kubernetes API server for Service and Endpoint changes and programs iptables rules in the kernel's netfilter framework to direct traffic to the appropriate backend Pods, providing efficient NAT-based load balancing without requiring a userspace proxy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
userspace
Why it's wrong here
In userspace mode, kube-proxy runs a userspace proxy that listens directly on the service ClusterIP and forwards each packet to a randomly selected backend pod. It does not rely on iptables rules for the actual traffic routing, but rather on socket-level connections in user space. This mode incurs heavy overhead from copying traffic between kernel and user space, making it significantly slower and less scalable than kernel-space modes. It was the original kube-proxy implementation but is now deprecated.
- ✗
ipvs
Why it's wrong here
IPVS mode leverages the Linux kernel's IP Virtual Server (IPVS) module, which uses a hash-based lookup table rather than a chain of iptables rules to map service virtual IPs to real endpoints. This design supports a much larger number of services with better performance and offers multiple load-balancing schedulers (e.g., round-robin, least connections). However, it is not the default mode; the cluster must have the appropriate ipvs kernel modules loaded, and it requires explicit configuration via --proxy-mode=ipvs.
- ✓
iptables
Why this is correct
iptables mode is the default kube-proxy mode and uses a carefully constructed set of iptables rules (typically DNAT and REDIRECT) to handle Service traffic. For each Service and its endpoints, kube-proxy creates separate rules that are evaluated in a linear chain; the kernel rewrites the destination IP of a packet to one of the selected backend pod IPs. This mode operates entirely in kernel space, avoiding user-space copying while providing reliable and predictable behavior, although the linear rule traversal can introduce latency with thousands of Services.
- ✗
nftables
Why it's wrong here
nftables is the modern replacement for iptables in the Linux kernel, but it is not a supported kube-proxy mode in standard Kubernetes releases. As of the current stable versions, kube-proxy offers userspace, iptables, ipvs, and kernelspace modes on Windows, with no production-ready nftables backend. While there has been experimental work on an nftables proxy, it is not available by default and therefore cannot be used to handle Service traffic in a typical cluster.
Visual reference
Go deeper
Related to this question
Learn chapter
Kubernetes Architecture Overview
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.