Courseiva
Kubernetes Fundamentals →mediumMultiple Select

KCNA Kubernetes Fundamentals Practice Question

A team is designing a Kubernetes architecture for a new application. They need to understand which components are part of the control plane and which run on worker nodes. Which TWO of the following components run on every worker node in a standard Kubernetes cluster? (Choose two.)

⚠ Common exam trap

The trap here is mixing control plane components with node components, especially assuming kube-scheduler or kube-controller-manager run on workers because they manage workloads.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kube-proxy

kubelet and kube-proxy are the two components that run on every worker node. kubelet manages Pods on the node, and kube-proxy handles Service networking. The scheduler, etcd, and controller manager are control plane components.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    kube-proxy

    Why this is correct

    kube-proxy runs on every worker node and maintains network rules that allow communication to Pods from inside or outside the cluster. It implements Service abstraction by programming iptables or IPVS rules, enabling load balancing across Pod endpoints.

  • ✗

    kube-controller-manager

    Why it's wrong here

    kube-controller-manager runs controllers that regulate cluster state, such as the ReplicaSet controller. It is a control plane component and does not run on worker nodes. Its presence on workers would not contribute to running Pods and is not standard.

  • ✗

    kube-scheduler

    Why it's wrong here

    kube-scheduler is a control plane component, not a worker node component. It watches for unscheduled Pods and assigns them to nodes. Running it on worker nodes would be redundant and is not part of a standard worker node setup.

  • ✓

    kubelet

    Why this is correct

    kubelet is an agent that runs on every worker node. It receives PodSpecs from the API server, ensures the described containers are running, and reports node and Pod status back to the control plane. Without kubelet, the node cannot run Pods.

  • ✗

    etcd

    Why it's wrong here

    etcd is the distributed key-value store that holds cluster state. It runs on control plane nodes, not on every worker node. Worker nodes communicate with the API server, which in turn talks to etcd, but they do not host etcd themselves.

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.