Courseiva
Container Orchestration →hardMultiple Choice

KCNA Container Orchestration Practice Question

A Kubernetes cluster is experiencing network latency. The team suspects that the number of services and endpoints is causing iptables performance degradation. Which CNI plugin or network policy approach is most likely to improve performance?

⚠ Common exam trap

Watch out — candidates often assume any CNI change or network policy adjustment can fix iptables performance, but only eBPF-based solutions fundamentally change the data path to avoid iptables scaling limitations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an eBPF-based CNI plugin like Cilium

C is correct because eBPF-based CNI plugins like Cilium bypass the traditional iptables chains entirely, using a kernel-level BPF (Berkeley Packet Filter) program to handle service load balancing and network policy enforcement. This eliminates the O(n) scaling issue of iptables rules with the number of services and endpoints, significantly reducing latency in large clusters.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Switch to Flannel with host-gw backend

    Why it's wrong here

    Flannel's host-gw backend still relies on iptables for service load balancing, so endpoint growth continues degrading rule traversal; it changes pod routing, not service implementation. It is tempting because host-gw genuinely improves pod-to-pod throughput by avoiding overlay encapsulation, and would be correct if the latency stem concerned VXLAN overlay overhead rather than iptables service scaling.

  • ✗

    Use Calico with iptables mode

    Why it's wrong here

    Calico in iptables mode still programs service and endpoint rules into iptables chains, so the degradation the team suspects persists unchanged. It is tempting because Calico is a capable CNI offering rich policy and routing options, and would be the right answer if the requirement were advanced network policy enforcement rather than replacing iptables-based service load balancing.

  • ✓

    Use an eBPF-based CNI plugin like Cilium

    Why this is correct

    Cilium replaces iptables with eBPF programs attached in the kernel, giving O(1) service lookup instead of sequential rule traversal. As services and endpoints grow, iptables latency scales linearly; eBPF hash-map lookups stay constant, directly resolving the degradation described.

  • ✗

    Apply a default-deny NetworkPolicy

    Why it's wrong here

    A default-deny NetworkPolicy governs which pods may communicate, not how the CNI implements service routing, so it leaves the iptables rule-chain overhead untouched. It is tempting because default-deny is genuinely valuable for segmentation and least-privilege traffic control, and would be correct when the requirement is restricting pod-to-pod communication rather than reducing packet-processing latency.

About these practice questions

This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.