Courseiva
Kubernetes Fundamentals →easyMultiple Choice

KCNA Kubernetes Fundamentals Practice Question

Which component is the primary entry point for all administrative tasks and API requests in a Kubernetes control plane?

⚠ Common exam trap

A common misconception is that etcd is the primary entry point because it stores all cluster data, but the trap is that etcd is a backend storage layer with no direct API exposure to users or external components. The kube-apiserver is the only component that exposes the Kubernetes API and handles all administrative requests.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kube-apiserver

The kube-apiserver is the front-end of the Kubernetes control plane and the only component that directly interacts with etcd. All administrative tasks (via kubectl), API requests from pods, and internal control plane components (scheduler, controller-manager) must pass through the kube-apiserver, which validates and processes them before persisting state or triggering actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    kube-apiserver

    Why this is correct

    kube-apiserver exposes the REST API that every administrative tool and internal component calls, validating and persisting objects to etcd. It is the sole entry point for kubectl requests and control-plane communication, satisfying the stem's requirement for the primary administrative entry point.

  • ✗

    etcd

    Why it's wrong here

    etcd is the distributed key-value store holding cluster state, not the request entry point; it only serves the API server. It is tempting because every object ultimately persists there, and it would be the answer if the question asked where cluster state is stored rather than which component accepts administrative and API requests.

  • ✗

    kube-scheduler

    Why it's wrong here

    kube-scheduler watches for newly created pods and assigns them to nodes; it does not serve the API. It is tempting because it is a control-plane component, but the API server is the entry point, with scheduler, controller manager and etcd all communicating through it.

  • ✗

    kube-controller-manager

    Why it's wrong here

    kube-controller-manager runs reconciliation loops that watch the API server and drive actual state toward desired state; it never accepts external administrative or API requests. It is tempting because it is a core control-plane component, and it would be correct if the question asked which component manages controllers such as node and replication controllers.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.