Courseiva

CKA Practice Question: Cluster Architecture, Installation and Configuration

Which TWO components are part of the Kubernetes control plane? (Choose TWO.)

⚠ Common exam trap

A common mix-up: candidates confuse node-level components (kubelet, kube-proxy, container runtime) with control plane components, especially because kubelet and kube-proxy are critical for cluster operation but run on every node, not just the control plane.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kube-apiserver

The Kubernetes control plane is the set of components that make global cluster decisions and expose the cluster API, and it includes the kube-apiserver (B) and kube-scheduler (C). The kube-apiserver (B) is the front end of the control plane: it validates and processes REST requests, persists cluster state in etcd, and is the only component that talks directly to etcd. The kube-scheduler (C) is also a control-plane component: it watches for newly created Pods with no assigned node and selects a suitable node based on resource requirements, affinity/anti-affinity, taints and tolerations, and other scheduling policies. The other options are node-level components, not control-plane components: the container runtime (A) executes containers on a node, the kubelet (D) is the node agent that ensures containers described in PodSpecs are running and healthy, and kube-proxy (E) maintains network rules on nodes to implement Service networking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    container runtime

    Why it's wrong here

    Container runtime (like containerd or CRI-O) is the software that actually runs containers, and it must be installed on every node, including worker nodes. It is not part of the control plane; control plane components manage cluster state and orchestration, while the runtime just executes the container lifecycle. The kubelet on each node uses the container runtime via CRI to create pods, so it's a node-level component, not a control plane service.

  • ✓

    kube-apiserver

    Why this is correct

    The kube-apiserver is the front end of the Kubernetes control plane, exposing the Kubernetes API and acting as the primary interface for all cluster management. It validates and processes RESTful requests, persists state to etcd, and coordinates communication between control plane and worker nodes via controllers and other components. Without it, no kubectl command or cluster operation could be executed, making it the core gateway of the control plane.

  • ✓

    kube-scheduler

    Why this is correct

    The kube-scheduler is a control plane component responsible for assigning newly created pods to nodes based on resource requirements, policies, and affinity rules. It watches for unscheduled pods and makes binding decisions, considering factors like CPU/memory requests, taints/tolerations, and node labels. Though logically separate, it runs as a pod on control plane nodes, confirming its control plane membership.

  • ✗

    kubelet

    Why it's wrong here

    The kubelet is the primary node agent that runs on every worker node, not on control plane nodes. It registers the node with the API server and manages the lifecycle of pods assigned to that node, ensuring containers are healthy and running. The control plane does not include node agents; the kubelet is instead the supervisor that executes control plane decisions on the worker side.

  • ✗

    kube-proxy

    Why it's wrong here

    kube-proxy is a network proxy that runs on each node (typically as a DaemonSet) to implement service networking by managing iptables or IPVS rules for load balancing across pods. It is not a control plane component; it belongs to the data plane, handling cluster traffic forwarding on worker nodes. While it interacts with the API server for service configuration, its runtime role is entirely node-local.

About these practice questions

Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.