KCNA Kubernetes Fundamentals Practice Question
Which Kubernetes control plane component is responsible for storing the cluster state and configuration data?
⚠ Common exam trap
The exam often tests the misconception that kube-apiserver stores the cluster state because it is the central API endpoint, but the trap is that the API server is stateless and relies entirely on etcd for persistence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
etcd
etcd is the distributed key-value store that serves as Kubernetes' single source of truth for all cluster state and configuration data. It stores objects like Pods, Services, Deployments, and Secrets, and is the only component that holds persistent state. The kube-apiserver reads from and writes to etcd, but etcd itself is the storage backend.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kube-controller-manager
Why it's wrong here
The kube-controller-manager runs reconciliation loops that drive the cluster towards its desired state; it reads and writes state through the API server rather than holding it. It is tempting because it manages cluster state, but persistent storage of that state belongs to etcd, accessed via the kube-apiserver.
- ✓
etcd
Why this is correct
etcd is the distributed key-value store holding all cluster state, including object definitions, configuration and secrets, and is the only component the API server reads from and writes to. Losing etcd means losing the cluster's authoritative state, making it the control plane's backing store.
- ✗
kube-apiserver
Why it's wrong here
The kube-apiserver exposes the REST interface and validates requests, but it does not itself persist cluster state; it reads and writes to etcd. It is tempting because every state change passes through it, yet the component actually responsible for storing cluster state and configuration data is etcd.
- ✗
kube-scheduler
Why it's wrong here
kube-scheduler binds pending pods to nodes by evaluating resource requests, affinity and taints; it holds no persistent store. Cluster state and configuration live in etcd, the only control plane component with a durable key-value backend. Choosing kube-scheduler confuses scheduling decisions with state persistence, which etcd alone provides.
Go deeper
Related to this question
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
7 more ways this is tested on KCNA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which component of the Kubernetes control plane is responsible for storing the cluster state?
easy- A.kube-apiserver
- ✓ B.etcd
- C.kube-scheduler
- D.kube-controller-manager
Why B: etcd is the distributed key-value store that serves as Kubernetes' primary data store, persisting all cluster state including configuration, secrets, and resource specifications. The kube-apiserver is the only component that interacts directly with etcd, ensuring consistency and providing a RESTful interface for all other components and users.
Variation 2. Which component of the Kubernetes control plane is responsible for storing the cluster state?
easy- A.kube-scheduler
- B.kube-controller-manager
- ✓ C.etcd
- D.kube-apiserver
Why C: etcd is the distributed key-value store that serves as Kubernetes' single source of truth for cluster state. It stores all cluster data, including configuration, desired state, and current state of objects like Pods, Services, and Deployments. The kube-apiserver is the only component that directly communicates with etcd, ensuring consistency and transactional integrity.
Variation 3. Which component of the Kubernetes control plane is responsible for storing the cluster state?
medium- A.kube-scheduler
- ✓ B.etcd
- C.kube-apiserver
- D.kube-controller-manager
Why B: etcd is the distributed key-value store that serves as Kubernetes' single source of truth for cluster state, including all object definitions, configurations, and statuses. The control plane components (kube-apiserver, scheduler, controller-manager) are stateless and rely on etcd to persist and retrieve cluster data. Without etcd, the cluster cannot recover its state after a restart.
Variation 4. Which component of the Kubernetes control plane stores the cluster state?
easy- ✓ A.etcd
- B.kube-controller-manager
- C.kube-scheduler
- D.kube-apiserver
Why A: etcd is the distributed key-value store that serves as the single source of truth for the entire Kubernetes cluster. It stores all cluster state data, including configuration, secrets, and the desired state of every object (Pods, Deployments, Services, etc.). The kube-apiserver is the only component that directly communicates with etcd, ensuring that all state changes go through a consistent, versioned API.
Variation 5. Which Kubernetes component is responsible for storing the cluster state?
easy- A.kube-scheduler
- B.kube-apiserver
- ✓ C.etcd
- D.kube-controller-manager
Why C: etcd is a distributed, consistent key-value store used by Kubernetes to store all cluster data, including configuration, state, and metadata. It is the single source of truth for the cluster; without etcd, the cluster cannot maintain or recover its state. The kube-apiserver is the only component that communicates directly with etcd, but it is etcd itself that physically stores the data.
Variation 6. Which TWO statements correctly describe the purpose of etcd in a Kubernetes cluster?
medium- ✓ A.It stores the cluster state, including all Kubernetes objects.
- B.It manages network rules for Pod-to-Pod communication.
- C.It schedules Pods onto nodes based on resource availability.
- D.It exposes the Kubernetes API for external access.
- ✓ E.It is a distributed key-value store that provides high availability and consistency.
Why A: Option A is correct because etcd is the backing store for all Kubernetes cluster data: every API object (Pods, Services, ConfigMaps, Secrets, etc.) is serialized and persisted in etcd, making it the single source of truth for cluster state. Option E is correct because etcd is fundamentally a distributed key-value store built on the Raft consensus algorithm, which replicates data across members to deliver high availability and strong consistency (linearizable reads/writes). Option B is wrong because Pod-to-Pod network rules are implemented by the CNI plugin and kube-proxy (iptables/IPVS or eBPF), not etcd. Option C is wrong because Pod scheduling is the job of kube-scheduler, which watches the API server and binds Pods to nodes. Option D is wrong because the Kubernetes API is exposed by kube-apiserver; etcd only serves as its storage backend and is not itself an API endpoint for clients.
Variation 7. Which two statements correctly describe etcd in a Kubernetes cluster?
medium- ✓ A.It is a key-value store that holds cluster configuration and state
- B.It runs on every worker node
- C.It manages network rules for Services
- D.It implements the Kubernetes API
- ✓ E.It is a critical component that must be backed up regularly
Why A: Option A is correct because etcd is the distributed, consistent key-value store that persists all Kubernetes cluster data, including configuration, object definitions, and cluster state, making it the single source of truth for the control plane. Option E is correct because etcd is a critical component: losing its data can render the cluster unrecoverable, so regular backups (e.g., via etcdctl snapshot save) are essential for disaster recovery. Option B is wrong because etcd typically runs only on control plane nodes (or as an external cluster), not on every worker node. Option C is wrong because network rules for Services are handled by kube-proxy (and CNI plugins), not etcd. Option D is wrong because the Kubernetes API is implemented by the kube-apiserver, which reads from and writes to etcd rather than etcd implementing the API itself.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.