KCNA Kubernetes Fundamentals Practice Question
An administrator is troubleshooting a cluster and runs `kubectl get pods -n kube-system`. They see a Pod named `kube-apiserver-controlplane` running on the control plane node. Which statement best describes the role of this component?
⚠ Common exam trap
The trap here is conflating the API server with the scheduler or controller manager, since all three are control plane components that appear in kube-system.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It stores and serves the cluster's API, acting as the front end for all control plane communication.
The kube-apiserver is the central control plane component that exposes the Kubernetes API and is the sole client of etcd. It authenticates, authorizes, validates, and persists requests, and all other components interact with the cluster through it. Scheduling, container runtime management, and controller reconciliation are handled by separate components, not by the API server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It schedules Pods onto nodes by evaluating resource requests and node affinity.
Why it's wrong here
Scheduling is the responsibility of the kube-scheduler, which watches for unscheduled Pods and assigns them to nodes. The kube-apiserver does not make scheduling decisions; it only persists the binding that the scheduler produces. Confusing the API server with the scheduler is a common mistake because both are control plane components that interact with Pod objects.
- ✓
It stores and serves the cluster's API, acting as the front end for all control plane communication.
Why this is correct
The kube-apiserver exposes the Kubernetes API and is the only component that talks directly to etcd. All other components, including kubelet, kube-scheduler, and controllers, communicate through it. It validates and persists objects, performs admission control, and serves REST endpoints for kubectl and clients. This makes it the central hub of the control plane.
- ✗
It watches for changes to desired state and reconciles them by creating or deleting Pods.
Why it's wrong here
Reconciliation of desired state is performed by controllers such as the Deployment controller, ReplicaSet controller, and Job controller, which run inside kube-controller-manager. The kube-apiserver provides the API and storage but does not itself run reconciliation loops. It is the shared communication layer those controllers rely on, not the controller logic itself.
- ✗
It runs the container runtime and manages the lifecycle of containers on each node.
Why it's wrong here
Container lifecycle management on a node is handled by the kubelet together with the container runtime such as containerd or CRI-O. The kube-apiserver runs only on control plane nodes and does not execute containers. It receives status updates from kubelets but does not directly manage container processes.
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.