Courseiva
hardMultiple Choice

CKS Practice Question: A security policy requires that all communication…

A security policy requires that all communication to etcd be encrypted. Which two components must be configured with TLS certificates to achieve this? (Select two)

⚠ Common exam trap

Many exam-takers assume all control plane components (scheduler, controller-manager) communicate directly with etcd, but in reality only the kube-apiserver interacts with etcd, while the others only talk to the apiserver.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kube-apiserver

The kube-apiserver is the only control plane component that directly communicates with etcd. To encrypt this communication, TLS certificates must be configured on both the kube-apiserver (as client) and etcd (as server). The other components (kubelet, kube-scheduler, kube-controller-manager) do not directly interact with etcd, so they do not need etcd-specific TLS configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubelet

    Why it's wrong here

    The kubelet serves the node's own API endpoint; it does not terminate etcd client traffic, so its certificates cannot encrypt communication to etcd. It is tempting because kubelet TLS is a genuine hardening step, but that applies to securing kubelet-to-apiserver and node connections, not the etcd datastore.

  • ✓

    kube-apiserver

    Why this is correct

    The API server connects to etcd as a client.

  • ✗

    kube-scheduler

    Why it's wrong here

    The kube-scheduler communicates only with the API server and never contacts etcd directly, so no etcd TLS certificate applies. Scheduler TLS matters for API-server communication; encrypting etcd traffic requires configuring the API server and etcd server with certificates.

  • ✗

    kube-controller-manager

    Why it's wrong here

    The kube-controller-manager connects to the API server, not directly to etcd, so it presents no etcd client certificate. It would need TLS configuration when securing controller-manager-to-API-server traffic; etcd encryption requires the API server and etcd itself.

  • ✓

    etcd

    Why this is correct

    etcd must serve its client API over TLS, presenting a server certificate and key and verifying client certificates from the kube-apiserver. Without this peer configuration, the apiserver's TLS handshake fails, so etcd itself must be configured to encrypt all communication.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.