CKA Practice Question: Cluster Architecture, Installation and Configuration
Which of the following is NOT a control plane component in Kubernetes?
⚠ Common exam trap
Watch out — candidates often confuse kube-proxy as a control plane component because it interacts with the API server and is essential for networking, but it operates at the node level and is not part of the control plane's core management functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kube-proxy
kube-proxy is not a control plane component; it is a node-level (worker) component responsible for implementing network rules and handling service-to-pod traffic via iptables or IPVS. The control plane consists of kube-apiserver, etcd, kube-scheduler, and kube-controller-manager.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kube-scheduler
Why it's wrong here
The kube-scheduler is a control plane component that runs on the control plane nodes and selects which worker node will run a newly created pod by evaluating resource requirements, affinity rules, and other constraints. It is not a worker-node process like kubelet, and its decision-making role is essential to cluster orchestration. Thus, it is not the correct answer.
- ✗
etcd
Why it's wrong here
etcd is the distributed, consistent key-value store that holds the entire cluster state, including all Kubernetes objects, configuration, and metadata. It runs as a control plane component, and the kube-apiserver is the only component that interacts with it directly, ensuring strong consistency for cluster data. Because it resides on control plane nodes, it qualifies as a control plane component.
- ✓
kube-proxy
Why this is correct
kube-proxy is the correct answer because it is a node-level component that runs on every worker node, not on the control plane. Its job is to maintain network rules and handle traffic routing for Services, typically using iptables or IPVS, so it forwards requests to backend pods. Since it does not participate in cluster-wide control decisions, it is not a control plane component.
- ✗
kube-apiserver
Why it's wrong here
The kube-apiserver is the front end of the control plane and exposes the Kubernetes REST API, validating and processing all requests from clients, including kubectl commands and controller operations. It stores cluster state in etcd and coordinates other control plane components, making it a core control plane component. Therefore, choosing it would be incorrect.
Go deeper
Related to this question
Learn chapter
etcd Backup and Restore
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.