Courseiva
Container Orchestration →mediumMultiple Choice

KCNA Container Orchestration Practice Question

Which component is responsible for running containers in a Kubernetes node and implements the Container Runtime Interface (CRI)?

⚠ Common exam trap

CNCF often tests the misconception that kubelet directly runs containers, but in reality kubelet is only the orchestrator agent that delegates to a CRI-compliant runtime like containerd, making containerd the correct answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

containerd

containerd is the correct answer because it is the container runtime that directly manages container lifecycle operations (create, start, stop, delete) on a Kubernetes node and implements the Container Runtime Interface (CRI), which is the gRPC-based protocol that kubelet uses to interact with container runtimes. Kubernetes requires a CRI-compliant runtime, and containerd is a graduated CNCF project that fulfills this role by exposing the CRI API via its `cri` plugin.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubelet

    Why it's wrong here

    The kubelet is the node agent that manages pods and their volumes, but it does not run containers; it delegates that to the container runtime via the CRI. Naming kubelet is tempting because it is the primary node component, yet containerd or CRI-O is the runtime implementing CRI to actually execute containers.

  • ✗

    etcd

    Why it's wrong here

    etcd stores the cluster's key-value state — configuration, secrets and object definitions — and never executes workloads. It is tempting because it is a core control-plane component, and it would be the right answer to a question asking where cluster state or service discovery data is persisted.

  • ✗

    kube-proxy

    Why it's wrong here

    kube-proxy programs iptables or IPVS rules on each node to implement Service virtual IPs and load-balance traffic to Pods; it does not invoke a container runtime. It is tempting as a per-node daemon, and would be correct if the question asked how Service traffic reaches backend Pods.

  • ✓

    containerd

    Why this is correct

    containerd is a CRI-compliant container runtime that runs on each node, pulling images and managing container lifecycles for the kubelet. It satisfies the stem's requirement for the node component implementing the Container Runtime Interface, unlike kubelet (orchestrates) or the API server (control plane).

Go deeper

Related to this question

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.