KCNA Kubernetes Fundamentals Practice Question
Which Kubernetes component is the primary entry point for all administrative tasks and API requests?
⚠ Common exam trap
CNCF often tests the misconception that etcd is the primary entry point because it stores all cluster data, but the trap is that etcd is never accessed directly by users or external tools — all interactions must go through the kube-apiserver, which acts as the single gateway for security and consistency.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kube-apiserver
The kube-apiserver is the front-end of the Kubernetes control plane and the sole entry point for all administrative tasks and API requests. It validates and processes RESTful API calls (using JSON/YAML over HTTP/HTTPS) before persisting state to etcd or delegating work to other controllers. Without the API server, no kubectl command, automation script, or internal component can interact with the cluster.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kube-controller-manager
Why it's wrong here
kube-controller-manager runs reconciliation loops that drive cluster state toward the desired configuration; it does not receive API requests. It is tempting because it is a core control-plane component, and it would be correct when asking which component manages controllers such as node lifecycle.
- ✗
etcd
Why it's wrong here
etcd is the distributed key-value store holding cluster state, not the request entry point. It is tempting because it is central to cluster operation, and it would be correct when the question asks where Kubernetes persists configuration and state data.
- ✓
kube-apiserver
Why this is correct
kube-apiserver exposes the REST API that kubectl, controllers and schedulers all call; it is the only component that reads and writes etcd. Every administrative task therefore passes through it, making it the cluster's single entry point.
- ✗
kube-scheduler
Why it's wrong here
kube-scheduler assigns pending pods to nodes by evaluating resource requests and constraints; it never receives client requests. It is tempting because scheduling is a control-plane function, but the API server is the sole entry point for administrative tasks, with scheduler watching it for unscheduled pods.
Go deeper
Related to this question
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.