KCNA Container Orchestration Practice Question
Which component is responsible for running containers in a Kubernetes node and implements the Container Runtime Interface (CRI)?
⚠ Common exam trap
CNCF often tests the misconception that kubelet directly runs containers, but in reality kubelet is only the orchestrator agent that delegates to a CRI-compliant runtime like containerd, making containerd the correct answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
containerd
containerd is the correct answer because it is the container runtime that directly manages container lifecycle operations (create, start, stop, delete) on a Kubernetes node and implements the Container Runtime Interface (CRI), which is the gRPC-based protocol that kubelet uses to interact with container runtimes. Kubernetes requires a CRI-compliant runtime, and containerd is a graduated CNCF project that fulfills this role by exposing the CRI API via its `cri` plugin.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubelet
Why it's wrong here
The kubelet is the node agent that manages pods and their volumes, but it does not run containers; it delegates that to the container runtime via the CRI. Naming kubelet is tempting because it is the primary node component, yet containerd or CRI-O is the runtime implementing CRI to actually execute containers.
- ✗
etcd
Why it's wrong here
etcd stores the cluster's key-value state — configuration, secrets and object definitions — and never executes workloads. It is tempting because it is a core control-plane component, and it would be the right answer to a question asking where cluster state or service discovery data is persisted.
- ✗
kube-proxy
Why it's wrong here
kube-proxy programs iptables or IPVS rules on each node to implement Service virtual IPs and load-balance traffic to Pods; it does not invoke a container runtime. It is tempting as a per-node daemon, and would be correct if the question asked how Service traffic reaches backend Pods.
- ✓
containerd
Why this is correct
containerd is a CRI-compliant container runtime that runs on each node, pulling images and managing container lifecycles for the kubelet. It satisfies the stem's requirement for the node component implementing the Container Runtime Interface, unlike kubelet (orchestrates) or the API server (control plane).
Go deeper
Related to this question
Learn chapter
Cluster Architecture and Lifecycle Management
Key term
ReplicaSet and Replication
A ReplicaSet ensures a specified number of identical pod instances are running at all times in Kubernetes, using replication to maintain availability and stability.
Key term
Container Runtime Interface
The Container Runtime Interface (CRI) is a standardized plugin protocol that allows Kubernetes to work with different container runtimes without needing to change its core code.
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.