KCNA Kubernetes Fundamentals Practice Question
Which Kubernetes component is the primary entry point for all administrative tasks and exposes the REST API?
⚠ Common exam trap
Inexperienced candidates often think that etcd is the primary entry point because it stores all cluster data, but the trap here is that etcd is a backend datastore with no REST API exposed to users—only the kube-apiserver serves as the administrative gateway.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kube-apiserver
The kube-apiserver is the front-end of the Kubernetes control plane and the sole component that exposes the Kubernetes REST API. All administrative tasks—whether performed via kubectl, the Kubernetes dashboard, or direct API calls—must go through the API server, which validates and processes requests before storing state in etcd. Without the API server, no other component (scheduler, controller-manager, etc.) can interact with the cluster state.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
kube-apiserver
Why this is correct
kube-apiserver exposes the Kubernetes REST API and is the sole component that reads and writes cluster state in etcd, making it the entry point for administrative tasks. Every kubectl command and internal controller request passes through it, satisfying the stem's requirement for the primary administrative gateway.
- ✗
kube-controller-manager
Why it's wrong here
kube-controller-manager runs reconciliation loops for controllers such as ReplicaSet and Node, but it neither exposes the REST API nor accepts kubectl commands. It is tempting because it drives cluster state, yet the API server is the sole entry point; controllers only watch and reconcile through it.
- ✗
etcd
Why it's wrong here
etcd is a distributed key-value store used solely for cluster state persistence, not for handling administrative requests or exposing a REST API for user-facing tasks. The primary entry point for administrative actions is the kube-apiserver, which validates and processes RESTful commands. etcd is tempting because it stores all cluster data, so one might assume it serves as the central access point, but it only responds to internal API server reads and writes, never to direct administrative commands.
- ✗
kube-scheduler
Why it's wrong here
kube-scheduler assigns pods to nodes based on resource requests and constraints; it does not expose the REST API or accept administrative commands. It is tempting because scheduling is central to cluster operation, but the API server is the entry point, with scheduler watching for unscheduled pods.
Go deeper
Related to this question
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.