Courseiva
Services and Networking →easyMultiple Select

CKA Services and Networking Practice Question

Which TWO of the following are valid kube-proxy modes?

⚠ Common exam trap

Candidates often mistake 'userspace' as still being a valid mode, but it was officially removed in Kubernetes v1.26. Additionally, while eBPF is a popular technology for Kubernetes networking (e.g., Cilium), it is not an official built-in kube-proxy mode.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ipvs

Options C and D are correct because kube-proxy officially supports ipvs and iptables as its two main production-ready proxy modes: ipvs mode uses the Linux IPVS (IP Virtual Server) load balancer in the kernel for better scalability and performance with large numbers of services, while iptables mode programs netfilter rules to implement Service load balancing and is the long-standing default on most clusters. Both are documented, selectable via the --proxy-mode flag (e.g., --proxy-mode=ipvs or --proxy-mode=iptables), and are the modes Kubernetes validates and maintains. Option A (eBPF) is not a kube-proxy mode; eBPF-based service handling is provided by alternative CNI/dataplane implementations such as Cilium, not by kube-proxy itself. Option B (userspace) was a legacy kube-proxy mode but is deprecated and removed in modern Kubernetes, so it is not a valid current answer. Option E (kernelnet) is not a real kube-proxy mode at all.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    eBPF

    Why it's wrong here

    eBPF is not a built-in kube-proxy mode; some implementations use it, but it's not standard.

  • ✗

    userspace

    Why it's wrong here

    Userspace mode is deprecated and removed in recent versions.

  • ✓

    ipvs

    Why this is correct

    Correct. ipvs is a supported mode.

  • ✓

    iptables

    Why this is correct

    Correct. iptables is the default mode.

  • ✗

    kernelnet

    Why it's wrong here

    KernelNet is not a kube-proxy mode.

About these practice questions

Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.