CKA Practice Question: Cluster Architecture, Installation and Configuration
Which THREE of the following are components of the Kubernetes control plane? (Choose THREE.)
⚠ Common exam trap
CNCF often tests the distinction between control plane components and node-level agents, so candidates mistakenly select kubelet or kube-proxy because they are essential to cluster operation, but they are not part of the control plane itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kube-apiserver
The Kubernetes control plane consists of the components that make global cluster decisions and store cluster state. kube-apiserver (A) is correct because it exposes the Kubernetes API and serves as the front end of the control plane, handling all REST requests and validating/updating objects in etcd. kube-scheduler (B) is correct because it watches for newly created Pods with no assigned node and selects a suitable node for them to run on. etcd (C) is correct because it is the consistent, highly-available key-value store that persists all cluster data and is the backing store for the API server. kubelet (D) is not a control plane component; it is a node agent that runs on each worker node and manages Pods and containers on that node. kube-proxy (E) is also not a control plane component; it is a node-level network proxy that implements Service networking rules on each node.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
kube-apiserver
Why this is correct
The kube-apiserver is the front-end of the Kubernetes control plane: it exposes the Kubernetes REST API and handles all read/write operations to the cluster's desired state. Every request—whether from kubectl, pods, or other components—passes through it for authentication, authorization, admission control, and validation before it is persisted. It is the only component that communicates directly with etcd, making it the central gateway for all cluster interactions.
- ✓
kube-scheduler
Why this is correct
The kube-scheduler is the control plane component responsible for assigning newly created Pods to nodes. It watches the API server for unscheduled Pods and runs a two-phase algorithm: filtering out nodes that fail resource or constraint requirements, then scoring the remaining nodes based on factors like resource spread and locality. The scheduler does not actually launch or run Pods; it only selects the optimal node, which the kubelet then executes.
- ✓
etcd
Why this is correct
etcd is a distributed, consistent key-value store that serves as Kubernetes' backing database for all cluster state. It stores every Kubernetes object, including configurations, desired states, and cluster metadata, and uses the Raft consensus protocol to maintain strong consistency and high availability. The kube-apiserver is the sole client that reads from and writes to etcd, so losing etcd effectively corrupts or destroys the entire cluster; it is unequivocally a control plane component.
- ✗
kubelet
Why it's wrong here
The kubelet is the primary node agent that runs on every worker node, not in the control plane. Its role is to communicate with the API server to receive Pod specifications and then ensure the containers defined in those Pods are started, healthy, and comply with the desired state. Because it runs at the node level and manages the local container runtime, it is considered a node-level component, not one of the three control plane components asked for.
- ✗
kube-proxy
Why it's wrong here
kube-proxy is a network proxy that runs on each node and implements the Kubernetes Service abstraction by programming iptables or IPVS rules to route traffic to backend Pods. It handles load balancing and service discovery for ClusterIP services, but it is a per-node data-plane component, not a global controller in the control plane. Thus, while it is essential to cluster networking, it is not one of the three control plane components: kube-apiserver, kube-scheduler, and etcd.
Go deeper
Related to this question
Learn chapter
Services and Networking Fundamentals
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
Kubernetes Node Roles
Kubernetes Node Roles are labels assigned to machines in a cluster that define whether a node runs application containers (worker) or manages the cluster (control plane).
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.