CKA Practice Question: Cluster Architecture, Installation and Configuration
Which TWO components are part of the Kubernetes control plane? (Choose TWO.)
⚠ Common exam trap
A common mix-up: candidates confuse node-level components (kubelet, kube-proxy, container runtime) with control plane components, especially because kubelet and kube-proxy are critical for cluster operation but run on every node, not just the control plane.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kube-apiserver
The Kubernetes control plane is the set of components that make global cluster decisions and expose the cluster API, and it includes the kube-apiserver (B) and kube-scheduler (C). The kube-apiserver (B) is the front end of the control plane: it validates and processes REST requests, persists cluster state in etcd, and is the only component that talks directly to etcd. The kube-scheduler (C) is also a control-plane component: it watches for newly created Pods with no assigned node and selects a suitable node based on resource requirements, affinity/anti-affinity, taints and tolerations, and other scheduling policies. The other options are node-level components, not control-plane components: the container runtime (A) executes containers on a node, the kubelet (D) is the node agent that ensures containers described in PodSpecs are running and healthy, and kube-proxy (E) maintains network rules on nodes to implement Service networking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
container runtime
Why it's wrong here
Container runtime (like containerd or CRI-O) is the software that actually runs containers, and it must be installed on every node, including worker nodes. It is not part of the control plane; control plane components manage cluster state and orchestration, while the runtime just executes the container lifecycle. The kubelet on each node uses the container runtime via CRI to create pods, so it's a node-level component, not a control plane service.
- ✓
kube-apiserver
Why this is correct
The kube-apiserver is the front end of the Kubernetes control plane, exposing the Kubernetes API and acting as the primary interface for all cluster management. It validates and processes RESTful requests, persists state to etcd, and coordinates communication between control plane and worker nodes via controllers and other components. Without it, no kubectl command or cluster operation could be executed, making it the core gateway of the control plane.
- ✓
kube-scheduler
Why this is correct
The kube-scheduler is a control plane component responsible for assigning newly created pods to nodes based on resource requirements, policies, and affinity rules. It watches for unscheduled pods and makes binding decisions, considering factors like CPU/memory requests, taints/tolerations, and node labels. Though logically separate, it runs as a pod on control plane nodes, confirming its control plane membership.
- ✗
kubelet
Why it's wrong here
The kubelet is the primary node agent that runs on every worker node, not on control plane nodes. It registers the node with the API server and manages the lifecycle of pods assigned to that node, ensuring containers are healthy and running. The control plane does not include node agents; the kubelet is instead the supervisor that executes control plane decisions on the worker side.
- ✗
kube-proxy
Why it's wrong here
kube-proxy is a network proxy that runs on each node (typically as a DaemonSet) to implement service networking by managing iptables or IPVS rules for load balancing across pods. It is not a control plane component; it belongs to the data plane, handling cluster traffic forwarding on worker nodes. While it interacts with the API server for service configuration, its runtime role is entirely node-local.
Go deeper
Related to this question
Learn chapter
Troubleshooting Networking and Services
Key term
Taints and Tolerations
Taints and tolerations are Kubernetes features that control which pods can be scheduled onto which nodes by marking nodes with a taint and allowing pods to declare a toleration to the taint.
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
About these practice questions
Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.