Courseiva

CKA Practice Question: Cluster Architecture, Installation and Configuration

Which TWO components are part of the Kubernetes control plane? (Select 2)

⚠ Common exam trap

It's easy for candidates to confuse node-level components like kubelet and kube-proxy with control plane components, because they are essential for cluster operation but run on worker nodes, not on the control plane nodes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

etcd

Option A, etcd, is correct because it is the control plane's distributed key-value store that persistently holds all cluster state and configuration data, which the API server reads and writes. Option E, kube-apiserver, is correct because it is the central control plane component that exposes the Kubernetes API, validates and processes REST requests, and is the entry point through which all other components interact with the cluster. The unmarked options do not belong: kubelet (B) is a node agent that runs on each worker node to manage pods and containers, kube-proxy (C) is a node-level network proxy implementing Service networking rules, and the container runtime (D) is the node software (e.g., containerd or CRI-O) that actually runs containers — all three are node components, not control plane components.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    etcd

    Why this is correct

    etcd is the control plane's distributed key-value store, holding all cluster state and configuration. The API server reads and writes every object through it, making etcd a required control plane component rather than a worker node process.

  • ✗

    kubelet

    Why it's wrong here

    kubelet is the node agent that starts and monitors pods via the container runtime; it runs on every worker node, not the control plane. It is tempting because it is essential cluster machinery, and would be correct when asked which component registers nodes and reports pod status.

  • ✗

    kube-proxy

    Why it's wrong here

    kube-proxy runs on each node, implementing Service virtual IPs and load balancing for pod traffic; it is a node component, not control plane. It is tempting because it is core to cluster networking, and would be correct when asked which components run on worker nodes.

  • ✗

    container runtime

    Why it's wrong here

    The container runtime executes containers on each node, invoked by the kubelet; it is a node-level dependency, not a control plane component. It is tempting because Kubernetes cannot run workloads without it, and would be correct when listing software required on worker nodes.

  • ✓

    kube-apiserver

    Why this is correct

    The kube-apiserver is a core control plane component, exposing the Kubernetes API that every other component and user interacts with. It validates and processes REST requests, then persists cluster state to etcd, satisfying the stem's requirement for a control plane member rather than a worker node component such as kubelet or kube-proxy.

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.