KCNA Kubernetes Fundamentals Practice Question
What is the function of kube-proxy on a worker node?
⚠ Common exam trap
A common misconception is that kube-proxy handles pod lifecycle or node health reporting, when in fact those are kubelet responsibilities. Candidates often confuse the 'proxy' name with general node management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It implements part of the Kubernetes Service concept by managing network rules
kube-proxy runs on each worker node and is responsible for implementing the Kubernetes Service abstraction by managing network rules (e.g., iptables, IPVS, or userspace mode). It watches the API server for Service and EndpointSlice changes and configures local packet filtering or forwarding rules to route traffic to the correct backend pods, enabling load balancing and service discovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It ensures the desired number of pods are running
Why it's wrong here
Maintaining the desired pod count is the job of the ReplicaSet controller inside kube-controller-manager, not kube-proxy. It is tempting because kube-proxy runs on every worker node alongside kubelet, but its actual role is programming iptables or IPVS rules so Service virtual IPs reach backing pods.
- ✗
It runs the container runtime
Why it's wrong here
Running containers is the container runtime's task, invoked by kubelet via the CRI, not kube-proxy. It is tempting because kube-proxy is a node-level daemon like kubelet, but it handles Service traffic routing through iptables or IPVS rules rather than executing container processes.
- ✗
It reports node status to the control plane
Why it's wrong here
Reporting node status is kubelet's responsibility, sending NodeStatus updates to the API server. It is tempting because kube-proxy is also a per-node daemon, but its function is implementing Service load balancing by programming iptables or IPVS rules, not communicating node health.
- ✓
It implements part of the Kubernetes Service concept by managing network rules
Why this is correct
kube-proxy watches Services and Endpoints via the API server, then programs iptables or IPVS rules on each node to load-balance traffic to backing pods. This implements the Service abstraction's virtual IP and routing behaviour at the data plane.
Go deeper
Related to this question
Learn chapter
Services and Network Connectivity
Key term
ReplicaSet and Replication
A ReplicaSet ensures a specified number of identical pod instances are running at all times in Kubernetes, using replication to maintain availability and stability.
Key term
Kubernetes API Primitives
Kubernetes API Primitives are the basic building blocks that the Kubernetes API uses to represent and manage the state of a cluster, such as Pods, Services, Deployments, and Namespaces.
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on KCNA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. What is the purpose of kube-proxy on a worker node?
medium- A.To run the container runtime
- B.To store cluster configuration data
- ✓ C.To implement network rules and handle service traffic routing
- D.To monitor pod health and restart unhealthy containers
Why C: Kube-proxy is the component responsible for implementing network rules on each worker node, enabling service abstraction by managing IP tables or IPVS rules to route traffic to the appropriate pods. It handles service discovery and load balancing for ClusterIP, NodePort, and LoadBalancer service types, ensuring that traffic destined for a service is correctly forwarded to healthy pod endpoints.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.