Courseiva

CKA Practice Question: Cluster Architecture, Installation and Configuration

Which TWO of the following are responsibilities of the kube-controller-manager?

⚠ Common exam trap

A common mix-up: candidates confuse the responsibilities of the kube-controller-manager with those of the kube-scheduler or kube-proxy, especially because all three components run on the control plane and interact with the API server.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Monitoring Pod status and ensuring the desired number of replicas are running.

Option A is correct because the kube-controller-manager runs the ReplicaSet (and ReplicationController) controller, which continuously watches Pod status via the API server and creates or deletes Pods so that the actual number of replicas matches the desired count in the spec. Option E is correct because the kube-controller-manager also runs the endpoints controller (and endpointslice controller), which populates Endpoints/EndpointSlice objects for Services by tracking the readiness and IP addresses of the Pods selected by each Service's selector. Option B is wrong because maintaining network rules on nodes is the job of the kube-proxy component, not the kube-controller-manager. Option C is wrong because assigning Pods to nodes is the responsibility of the kube-scheduler, which filters and scores nodes based on resource availability and constraints. Option D is wrong because managing cloud provider-specific resources such as load balancers is handled by the cloud-controller-manager (cloud controller manager), which was split out from the kube-controller-manager.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Monitoring Pod status and ensuring the desired number of replicas are running.

    Why this is correct

    This is the core responsibility of the ReplicaSet controller within the kube-controller-manager. It continuously watches Pod state through the API server, and when actual replicas differ from the desired count—due to failures, scaling, or deletion—it creates or terminates Pods to reconcile the cluster to the declarative spec. This is a classic example of a controller using the control loop pattern, and it is exactly the kind of work the kube-controller-manager performs.

  • ✗

    Maintaining network rules on nodes.

    Why it's wrong here

    Network rules on nodes, such as DNAT rules for Service ClusterIPs and load balancing, are implemented by kube-proxy, not the kube-controller-manager. kube-proxy runs as a DaemonSet on each node and configures iptables, IPVS, or eBPF to route traffic to backend Pods. While the kube-controller-manager manages the Service and Endpoints objects that define the desired routing, the actual maintenance of the node-level network rules is kube-proxy's job.

  • ✗

    Assigning Pods to nodes based on resource availability.

    Why it's wrong here

    Deciding which node should host a new or unscheduled Pod is exclusively the kube-scheduler's responsibility. The scheduler evaluates each pending Pod against node resources, affinities, taints, and other constraints, then binds it to a chosen node. The kube-controller-manager does not assign Pods to nodes; it only reacts to Pods that already have a node assignment (or lack one) to enforce replica counts.

  • ✗

    Managing cloud provider-specific resources like load balancers.

    Why it's wrong here

    Cloud provider integration, such as provisioning load balancers, volumes, or node lifecycle management, is handled by the cloud-controller-manager. In modern clusters this is a separate control plane component that contains cloud-specific controllers, while the core kube-controller-manager remains cloud-agnostic. Therefore, managing cloud resources like load balancers falls outside the scope of kube-controller-manager responsibilities.

  • ✓

    Managing endpoints for Services.

    Why this is correct

    This is another responsibility of the kube-controller-manager, specifically performed by the EndpointSlice controller (and legacy endpoints controller). It watches Services and backing Pods, then creates or updates EndpointSlice objects that track which Pod IPs and ports serve a given Service. These EndpointSlices are consumed by kube-proxy to program node network rules, but the controller itself is in the kube-controller-manager.

About these practice questions

This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.