Courseiva
Services and Networking →hardMultiple Choice

CKA Services and Networking Practice Question

You have a Service with endpoints for pods in different zones. You want kube-proxy to use a mode that provides better performance for large clusters and supports scheduling algorithms like least-connection. Which mode should you use?

⚠ Common exam trap

Many exam-takers assume iptables mode is the best for performance because it is the default, but they overlook that IPVS is specifically designed for high-performance load balancing with advanced scheduling algorithms, while iptables mode only supports random selection and suffers from linear rule traversal in large clusters.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ipvs mode

IPVS (IP Virtual Server) mode is correct because it uses the LVS (Linux Virtual Server) kernel module to provide a transport-layer load balancer that supports multiple scheduling algorithms, including least-connection (lc), round-robin (rr), and source hashing (sh). Unlike iptables, IPVS uses a hash table as the underlying data structure, which scales linearly with the number of services and endpoints, making it far more performant in large clusters with thousands of services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    userspace mode

    Why it's wrong here

    Userspace mode is a legacy kube-proxy implementation where traffic is routed from kernel space to user space and back via a proxy process. This constant context switching incurs a massive performance penalty and high latency. It has been deprecated for several releases and is highly inefficient for routing traffic across zones.

  • ✓

    ipvs mode

    Why this is correct

    IPVS (IP Virtual Server) mode operates in the Linux kernel space and utilizes hash tables, allowing it to scale efficiently to thousands of services. It supports advanced load-balancing algorithms, such as round-robin, least connection, and destination hashing, which are crucial for optimizing traffic distribution across different zones.

  • ✗

    iptables mode

    Why it's wrong here

    While iptables is the default kube-proxy mode, it relies on sequentially evaluating a linear chain of rules for every packet, which degrades performance at scale. Furthermore, its load-balancing capability is limited to probabilistic random selection, making it unable to implement sophisticated zone-aware or weighted scheduling algorithms.

  • ✗

    kernelspace mode

    Why it's wrong here

    Kernelspace mode is not a recognized or standard kube-proxy operational mode in Kubernetes. While kube-proxy leverages kernel-level technologies like IPVS and iptables to manage routing rules, there is no distinct mode named kernelspace mode in the configuration options.

About these practice questions

This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.