CKA Services and Networking Practice Question
Which TWO of the following are valid kube-proxy modes?
⚠ Common exam trap
Candidates often mistake 'userspace' as still being a valid mode, but it was officially removed in Kubernetes v1.26. Additionally, while eBPF is a popular technology for Kubernetes networking (e.g., Cilium), it is not an official built-in kube-proxy mode.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ipvs
Options C and D are correct because kube-proxy officially supports ipvs and iptables as its two main production-ready proxy modes: ipvs mode uses the Linux IPVS (IP Virtual Server) load balancer in the kernel for better scalability and performance with large numbers of services, while iptables mode programs netfilter rules to implement Service load balancing and is the long-standing default on most clusters. Both are documented, selectable via the --proxy-mode flag (e.g., --proxy-mode=ipvs or --proxy-mode=iptables), and are the modes Kubernetes validates and maintains. Option A (eBPF) is not a kube-proxy mode; eBPF-based service handling is provided by alternative CNI/dataplane implementations such as Cilium, not by kube-proxy itself. Option B (userspace) was a legacy kube-proxy mode but is deprecated and removed in modern Kubernetes, so it is not a valid current answer. Option E (kernelnet) is not a real kube-proxy mode at all.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
eBPF
Why it's wrong here
eBPF is not a built-in kube-proxy mode; some implementations use it, but it's not standard.
- ✗
userspace
Why it's wrong here
Userspace mode is deprecated and removed in recent versions.
- ✓
ipvs
Why this is correct
Correct. ipvs is a supported mode.
- ✓
iptables
Why this is correct
Correct. iptables is the default mode.
- ✗
kernelnet
Why it's wrong here
KernelNet is not a kube-proxy mode.
Go deeper
Related to this question
Learn chapter
Troubleshooting Networking and Services
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
About these practice questions
Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.