KCNA Kubernetes Fundamentals Practice Question
A Service of type ClusterIP is created to expose a set of pods. How does the Service achieve load balancing to the pods?
⚠ Common exam trap
A common trap is confusing the control-plane role of the API server with the data-plane role of kube-proxy. The API server does not handle data-plane traffic for Services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The kube-proxy component on each node sets up network rules to forward traffic to the pods
Kube-proxy on each node implements load balancing for ClusterIP Services by creating iptables or IPVS rules that distribute traffic from the Service's virtual IP to the backend pods. These rules use a random or round-robin selection (depending on the mode) to forward packets to healthy pods, ensuring no single pod is overwhelmed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The API server routes traffic directly to the pods
Why it's wrong here
kube-proxy, not the API server, implements ClusterIP load balancing by writing iptables or IPVS rules that DNAT connections to endpoint pods. The API server only persists Service and EndpointSlice objects; it never sits in the data path. Direct API-server routing applies to neither ClusterIP nor any other Service type.
- ✓
The kube-proxy component on each node sets up network rules to forward traffic to the pods
Why this is correct
Kube-proxy runs on every node and programs iptables or IPVS rules that intercept traffic destined for the ClusterIP, then forwards each connection to one of the backing pod endpoints. This satisfies the stem's load-balancing requirement, distributing traffic across pods without any external load balancer.
- ✗
The kubelet configures the container runtime to route traffic
Why it's wrong here
The kubelet manages pod lifecycle and container runtime configuration on each node; it does not program Service load balancing. It is tempting because kubelet and kube-proxy both run per node, but kube-proxy writes iptables or IPVS rules translating the ClusterIP to pod endpoints.
- ✗
Using a cloud load balancer
Why it's wrong here
ClusterIP load balancing is performed by kube-proxy, which programs iptables or IPVS rules on each node to distribute connections across endpoint pods. A cloud load balancer is provisioned only by a Service of type LoadBalancer, which requests an external provider resource, so it plays no part in ClusterIP traffic handling.
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.