KCNA Kubernetes Fundamentals Practice Question
A team is designing a Kubernetes architecture for a new application. They need to understand which components are part of the control plane and which run on worker nodes. Which TWO of the following components run on every worker node in a standard Kubernetes cluster? (Choose two.)
⚠ Common exam trap
The trap here is mixing control plane components with node components, especially assuming kube-scheduler or kube-controller-manager run on workers because they manage workloads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kube-proxy
kubelet and kube-proxy are the two components that run on every worker node. kubelet manages Pods on the node, and kube-proxy handles Service networking. The scheduler, etcd, and controller manager are control plane components.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
kube-proxy
Why this is correct
kube-proxy runs on every worker node and maintains network rules that allow communication to Pods from inside or outside the cluster. It implements Service abstraction by programming iptables or IPVS rules, enabling load balancing across Pod endpoints.
- ✗
kube-controller-manager
Why it's wrong here
kube-controller-manager runs controllers that regulate cluster state, such as the ReplicaSet controller. It is a control plane component and does not run on worker nodes. Its presence on workers would not contribute to running Pods and is not standard.
- ✗
kube-scheduler
Why it's wrong here
kube-scheduler is a control plane component, not a worker node component. It watches for unscheduled Pods and assigns them to nodes. Running it on worker nodes would be redundant and is not part of a standard worker node setup.
- ✓
kubelet
Why this is correct
kubelet is an agent that runs on every worker node. It receives PodSpecs from the API server, ensures the described containers are running, and reports node and Pod status back to the control plane. Without kubelet, the node cannot run Pods.
- ✗
etcd
Why it's wrong here
etcd is the distributed key-value store that holds cluster state. It runs on control plane nodes, not on every worker node. Worker nodes communicate with the API server, which in turn talks to etcd, but they do not host etcd themselves.
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.