CKA Practice Question: Cluster Architecture, Installation and Configuration
Which of the following is a core control plane component of Kubernetes?
⚠ Common exam trap
Test-takers frequently confuse node-level components (kubelet, CRI-O) or cluster add-ons (CoreDNS) with core control plane components, because all are essential for a working cluster but only the kube-apiserver, kube-controller-manager, kube-scheduler, and etcd are considered core control plane components.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kube-apiserver
The kube-apiserver is the front-end of the Kubernetes control plane and the only component that directly interacts with the etcd datastore. It validates and processes all REST API requests, making it the core control plane component responsible for exposing the Kubernetes API and managing the cluster state.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubelet
Why it's wrong here
The kubelet is an agent that runs on each worker node in the cluster, ensuring that containers are running in a Pod as specified by PodSpecs. While it communicates directly with the control plane, it operates on the data plane to manage local container lifecycles rather than serving as a centralized control plane component.
- ✗
CoreDNS
Why it's wrong here
CoreDNS is a flexible, extensible DNS server that runs as a cluster addon to provide service discovery and name resolution within the Kubernetes cluster. Although essential for networking, it is deployed as a set of standard Pods on worker nodes rather than being a core, built-in control plane binary like the scheduler or controller manager.
- ✓
kube-apiserver
Why this is correct
The kube-apiserver is the central administrative hub of the Kubernetes control plane, exposing the HTTP API that lets users, external components, and internal parts communicate. It validates and configures data for state objects, processes REST operations, and acts as the sole gateway to the etcd datastore.
- ✗
CRI-O
Why it's wrong here
CRI-O is a lightweight, OCI-compliant container runtime designed specifically for Kubernetes to pull images and run container workloads. It operates at the node level, receiving instructions from the local kubelet via the Container Runtime Interface (CRI), making it a worker-node dependency rather than a control plane orchestrator.
Go deeper
Related to this question
Learn chapter
Installing Kubernetes with kubeadm
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
About these practice questions
Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.