KCNA Kubernetes Fundamentals Practice Question
Which component runs on every worker node and is responsible for ensuring that containers are running in a pod according to the pod specification?
⚠ Common exam trap
Many exam-takers confuse the kubelet with the container runtime, thinking the runtime itself reads the pod spec, when in fact the kubelet is the agent that interprets the spec and delegates container operations to the runtime via the Container Runtime Interface (CRI).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubelet
The kubelet is the primary node agent that runs on every worker node in a Kubernetes cluster. It registers the node with the API server, watches for PodSpecs assigned to its node, and ensures the containers described in those PodSpecs are running and healthy. It does this by interacting with the container runtime to create, start, and stop containers as needed, and it reports the node and pod status back to the control plane.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kube-scheduler
Why it's wrong here
The kube-scheduler assigns pods to nodes based on resource availability and policy, but it does not execute on worker nodes or manage container runtime. It is tempting because scheduling is a core control-plane function, yet the stem requires a node-level agent that enforces the pod specification by starting and monitoring containers—a task performed by the kubelet.
- ✓
kubelet
Why this is correct
The kubelet is the node agent that watches the API server for pods bound to its node and drives the container runtime to start, stop and health-check containers to match the pod specification. It runs on every worker node, exactly as the stem requires.
- ✗
container runtime
Why it's wrong here
The container runtime starts and stops containers but does not continuously reconcile actual pod state against the specification; that reconciliation is the kubelet's job. It is tempting because the runtime is genuinely responsible for executing containers, and would be the answer if the question asked what actually launches container processes on a node.
- ✗
kube-proxy
Why it's wrong here
kube-proxy maintains network rules on nodes for Service traffic, not pod lifecycle. It is tempting because it does run on every worker node, but the component that reconciles actual pod state with the pod specification is the kubelet, which starts, stops, and health-checks containers via the container runtime.
Go deeper
Related to this question
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.