KCNA Container Orchestration Practice Question
A Kubernetes cluster is experiencing network latency. The team suspects that the number of services and endpoints is causing iptables performance degradation. Which CNI plugin or network policy approach is most likely to improve performance?
⚠ Common exam trap
Watch out — candidates often assume any CNI change or network policy adjustment can fix iptables performance, but only eBPF-based solutions fundamentally change the data path to avoid iptables scaling limitations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use an eBPF-based CNI plugin like Cilium
C is correct because eBPF-based CNI plugins like Cilium bypass the traditional iptables chains entirely, using a kernel-level BPF (Berkeley Packet Filter) program to handle service load balancing and network policy enforcement. This eliminates the O(n) scaling issue of iptables rules with the number of services and endpoints, significantly reducing latency in large clusters.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Switch to Flannel with host-gw backend
Why it's wrong here
Flannel's host-gw backend still relies on iptables for service load balancing, so endpoint growth continues degrading rule traversal; it changes pod routing, not service implementation. It is tempting because host-gw genuinely improves pod-to-pod throughput by avoiding overlay encapsulation, and would be correct if the latency stem concerned VXLAN overlay overhead rather than iptables service scaling.
- ✗
Use Calico with iptables mode
Why it's wrong here
Calico in iptables mode still programs service and endpoint rules into iptables chains, so the degradation the team suspects persists unchanged. It is tempting because Calico is a capable CNI offering rich policy and routing options, and would be the right answer if the requirement were advanced network policy enforcement rather than replacing iptables-based service load balancing.
- ✓
Use an eBPF-based CNI plugin like Cilium
Why this is correct
Cilium replaces iptables with eBPF programs attached in the kernel, giving O(1) service lookup instead of sequential rule traversal. As services and endpoints grow, iptables latency scales linearly; eBPF hash-map lookups stay constant, directly resolving the degradation described.
- ✗
Apply a default-deny NetworkPolicy
Why it's wrong here
A default-deny NetworkPolicy governs which pods may communicate, not how the CNI implements service routing, so it leaves the iptables rule-chain overhead untouched. It is tempting because default-deny is genuinely valuable for segmentation and least-privilege traffic control, and would be correct when the requirement is restricting pod-to-pod communication rather than reducing packet-processing latency.
Go deeper
Related to this question
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.