CKA Practice Question: Cluster Architecture, Installation and Configuration
Which TWO of the following are control plane components?
⚠ Common exam trap
CNCF often tests the distinction between control plane and node components, and the trap here is that candidates mistakenly classify kube-proxy or kubelet as control plane components because they are essential for cluster operation, but they are not part of the control plane's core management layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
cloud-controller-manager
The cloud-controller-manager (A) is a control plane component because it runs cloud-specific controller loops (node, route, and service controllers) that interact with the underlying cloud provider's API, and it runs on the control plane alongside the API server and scheduler. etcd (C) is the control plane's consistent, highly-available key-value store that persists all cluster state and objects, making it a core control plane component. By contrast, kubelet (B) is a node agent that runs on each worker node and manages pod lifecycles via the CRI, so it is a node component, not control plane. The container runtime (D) is node-level software (e.g., containerd or CRI-O) that actually runs containers, and kube-proxy (E) is a node-level network proxy implementing Service rules via iptables/IPVS, so neither belongs to the control plane.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
cloud-controller-manager
Why this is correct
The cloud-controller-manager is a control plane component that runs cloud-specific controllers, such as those for node lifecycle, load balancers, and routing, by interacting with the cloud provider's API. It is scheduled only on control plane nodes and is built as a separate binary to isolate cloud dependencies from the core Kubernetes controllers. Because its entire function is to bridge the cluster to a cloud provider's infrastructure, it belongs exclusively to the control plane.
- ✗
kubelet
Why it's wrong here
kubelet is the agent that runs on every node, including worker nodes, to ensure that containers inside pods are running and healthy. It takes pod specifications from the API server and manages the container runtime on its local node. Since it executes on all nodes and manages local execution, it is a node-level component rather than a control plane component.
- ✓
etcd
Why this is correct
etcd is a distributed key-value store that holds the entire cluster's configuration, state, and metadata, making it a fundamental control plane component. It runs on control plane nodes and uses the Raft consensus algorithm to provide consistency and high availability. Without etcd, the control plane cannot maintain cluster state, so it is definitively part of the control plane.
- ✗
container runtime
Why it's wrong here
The container runtime is the software that actually runs containers, such as containerd or CRI-O, and it must be installed on every node that executes pods, including workers. Its job is to pull images, create containers, and manage their lifecycle, operating at the node level. It is not part of the control plane, as control plane pods themselves are run on nodes with a container runtime, but the runtime does not provide cluster-management functions.
- ✗
kube-proxy
Why it's wrong here
kube-proxy is a network proxy that runs on every node, including worker nodes, to implement Kubernetes Service semantics by maintaining iptables or IPVS rules. It forwards traffic to backend pods based on Service definitions, but it does not run exclusively on control plane nodes. Because its operation is node-local and essential for service routing on all nodes, it is a node component rather than a control plane component.
Go deeper
Related to this question
Learn chapter
etcd Backup and Restore
Key term
Kubernetes Node Roles
Kubernetes Node Roles are labels assigned to machines in a cluster that define whether a node runs application containers (worker) or manages the cluster (control plane).
Key term
Container Runtime
A container runtime is software that runs containers by using the host operating system's kernel to isolate processes, manage filesystem layers, and handle networking.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.