Courseiva

CKA Practice Question: Cluster Architecture, Installation and Configuration

Which THREE of the following are components of the Kubernetes control plane? (Choose THREE.)

⚠ Common exam trap

CNCF often tests the distinction between control plane components and node-level agents, so candidates mistakenly select kubelet or kube-proxy because they are essential to cluster operation, but they are not part of the control plane itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kube-apiserver

The Kubernetes control plane consists of the components that make global cluster decisions and store cluster state. kube-apiserver (A) is correct because it exposes the Kubernetes API and serves as the front end of the control plane, handling all REST requests and validating/updating objects in etcd. kube-scheduler (B) is correct because it watches for newly created Pods with no assigned node and selects a suitable node for them to run on. etcd (C) is correct because it is the consistent, highly-available key-value store that persists all cluster data and is the backing store for the API server. kubelet (D) is not a control plane component; it is a node agent that runs on each worker node and manages Pods and containers on that node. kube-proxy (E) is also not a control plane component; it is a node-level network proxy that implements Service networking rules on each node.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    kube-apiserver

    Why this is correct

    The kube-apiserver is the front-end of the Kubernetes control plane: it exposes the Kubernetes REST API and handles all read/write operations to the cluster's desired state. Every request—whether from kubectl, pods, or other components—passes through it for authentication, authorization, admission control, and validation before it is persisted. It is the only component that communicates directly with etcd, making it the central gateway for all cluster interactions.

  • ✓

    kube-scheduler

    Why this is correct

    The kube-scheduler is the control plane component responsible for assigning newly created Pods to nodes. It watches the API server for unscheduled Pods and runs a two-phase algorithm: filtering out nodes that fail resource or constraint requirements, then scoring the remaining nodes based on factors like resource spread and locality. The scheduler does not actually launch or run Pods; it only selects the optimal node, which the kubelet then executes.

  • ✓

    etcd

    Why this is correct

    etcd is a distributed, consistent key-value store that serves as Kubernetes' backing database for all cluster state. It stores every Kubernetes object, including configurations, desired states, and cluster metadata, and uses the Raft consensus protocol to maintain strong consistency and high availability. The kube-apiserver is the sole client that reads from and writes to etcd, so losing etcd effectively corrupts or destroys the entire cluster; it is unequivocally a control plane component.

  • ✗

    kubelet

    Why it's wrong here

    The kubelet is the primary node agent that runs on every worker node, not in the control plane. Its role is to communicate with the API server to receive Pod specifications and then ensure the containers defined in those Pods are started, healthy, and comply with the desired state. Because it runs at the node level and manages the local container runtime, it is considered a node-level component, not one of the three control plane components asked for.

  • ✗

    kube-proxy

    Why it's wrong here

    kube-proxy is a network proxy that runs on each node and implements the Kubernetes Service abstraction by programming iptables or IPVS rules to route traffic to backend Pods. It handles load balancing and service discovery for ClusterIP services, but it is a per-node data-plane component, not a global controller in the control plane. Thus, while it is essential to cluster networking, it is not one of the three control plane components: kube-apiserver, kube-scheduler, and etcd.

Go deeper

Related to this question

About these practice questions

This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.