Courseiva
Kubernetes Fundamentals →mediumMultiple Choice

KCNA Kubernetes Fundamentals Practice Question

Which component is responsible for ensuring that the containers in a pod are running as specified?

⚠ Common exam trap

Many exam-takers confuse the kube-controller-manager's role in managing controllers (like Deployments) with the actual node-level execution of containers, leading them to pick Option B instead of the kubelet.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubelet

The kubelet is the primary node agent that runs on each worker node. It receives PodSpec definitions from the API server (or from a local file/HTTP source for static pods) and ensures that the containers described in those PodSpecs are actually running and healthy. It does this by interacting with the container runtime (e.g., containerd or CRI-O) via the CRI to start, stop, and restart containers as needed, continuously reconciling the actual state with the desired state.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kube-apiserver

    Why it's wrong here

    The kube-apiserver validates and persists pod objects to etcd, then serves watch events; it does not act on the spec to start or restart containers. It is tempting because every pod creation passes through it, but reconciliation belongs to the controller and kubelet layers.

  • ✗

    kube-controller-manager

    Why it's wrong here

    The kube-controller-manager runs controllers that reconcile cluster state, such as replica counts and node lifecycle, not individual pod container status. It is tempting because it manages workloads, but the kubelet on each node ensures containers in a pod run as specified.

  • ✓

    kubelet

    Why this is correct

    The kubelet runs on each node as the primary agent, receiving PodSpecs and directly managing container lifecycles through the container runtime. It continuously reconciles actual container state against the declared specification, restarting or reporting containers that deviate, which satisfies the requirement that containers run as specified.

  • ✗

    kube-proxy

    Why it's wrong here

    kube-proxy programs iptables or IPVS rules on each node so Service virtual IPs reach the correct pod endpoints; it never reconciles container state against the pod spec. It is tempting because it runs on every node alongside the workload, but its remit is service load-balancing, not lifecycle enforcement.

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.