Courseiva
Kubernetes Fundamentals →easyMultiple Choice

KCNA Kubernetes Fundamentals Practice Question

Which component runs on every worker node and is responsible for ensuring that containers are running in a pod as specified in the PodSpec?

⚠ Common exam trap

A common mix-up: candidates confuse the kubelet with the container runtime, assuming the runtime itself reads PodSpecs, when in fact the kubelet is the orchestrator that translates PodSpecs into runtime actions via the CRI.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubelet

The kubelet is the primary node agent that runs on every worker node in a Kubernetes cluster. It is responsible for ensuring that containers described in a PodSpec are running and healthy, by interacting with the container runtime (e.g., containerd, CRI-O) to create, start, and monitor pods. The kubelet does not manage containers that were not created by Kubernetes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    container runtime

    Why it's wrong here

    The container runtime starts and stops individual containers on a node, but it acts on instructions from the kubelet and does not reconcile pod state against the PodSpec. It is tempting because it runs on every worker node and touches containers directly, yet it would be correct for a question about the component that actually executes containers.

  • ✗

    kube-proxy

    Why it's wrong here

    kube-proxy maintains network rules on nodes, implementing Service virtual IPs and load balancing for pod traffic; it never inspects or restarts containers. It is tempting because it does run on every worker node, but its remit is networking, so it would be correct for a question about Service routing rather than PodSpec reconciliation.

  • ✓

    kubelet

    Why this is correct

    The kubelet is the primary node agent that runs on every worker node, directly satisfying the stem’s constraint of ensuring containers run per the PodSpec. It achieves this by continuously polling the API server for assigned Pods, then using the container runtime (e.g., containerd) to create, start, and restart containers based on the PodSpec’s declared state, thereby enforcing the desired container lifecycle.

  • ✗

    kube-scheduler

    Why it's wrong here

    kube-scheduler runs as part of the control plane and selects which node an unscheduled pod should land on; it does not run on every worker node or keep containers running. It is tempting because scheduling concerns pods, but it would be correct for a question about node selection, not PodSpec enforcement.

About these practice questions

This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.