KCNA Kubernetes Fundamentals Practice Question
Which three components are part of the Kubernetes control plane? (Select THREE)
⚠ Common exam trap
CNCF often tests the distinction between control plane and worker node components, and the trap here is that candidates confuse kube-proxy or kubelet as control plane components because they are essential to cluster operation, but they actually run on every node and are not part of the control plane.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
etcd
etcd (A) is correct because it is the control plane's distributed key-value store that persists all cluster state and object data. kube-apiserver (B) is correct because it is the central control plane component that exposes the Kubernetes API and is the front end through which all other components communicate. kube-controller-manager (D) is correct because it runs the built-in controller loops that reconcile cluster state toward the desired state. kube-proxy (C) is not part of the control plane; it runs on each node to implement Service networking via iptables/IPVS rules. kubelet (E) is also not part of the control plane; it is the node agent that manages Pods and containers on each worker node.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
etcd
Why this is correct
etcd is the control plane's distributed key-value store, persisting all cluster state and configuration. It is one of the three core control plane components named in the KCNA syllabus, alongside the kube-apiserver and kube-controller-manager, so it satisfies the question's requirement for a control plane member.
- ✓
kube-apiserver
Why this is correct
kube-apiserver exposes the Kubernetes API and is the front end of the control plane, validating and processing every REST request. It is a core control plane component, so it satisfies the question's requirement for one of the three control plane members.
- ✗
kube-proxy
Why it's wrong here
kube-proxy programmes Service load-balancing rules on each node's data path; it is a node component, not a control-plane component. It is tempting because it is a core Kubernetes add-on present on every node, so it appears alongside genuine control-plane services in cluster diagrams.
- ✓
kube-controller-manager
Why this is correct
kube-controller-manager runs the built-in controllers that reconcile cluster state, such as node and replication controllers. It is a core control plane component, so it satisfies the question's requirement for one of the three control plane members.
- ✗
kubelet
Why it's wrong here
kubelet is a node agent that registers the node and runs pods via the container runtime; it does not participate in control-plane decision-making. It is tempting because kubelet is essential to cluster operation and appears in every node listing, so it is easily confused with the components that form the control plane.
Go deeper
Related to this question
Learn chapter
Kubernetes Networking and DNS
Key term
Pods and Containers
Pods are the smallest deployable units in Kubernetes that wrap one or more containers, sharing network and storage resources.
Key term
ReplicaSet and Replication
A ReplicaSet ensures a specified number of identical pod instances are running at all times in Kubernetes, using replication to maintain availability and stability.
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
8 more ways this is tested on KCNA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO components are part of the Kubernetes control plane? (Select exactly two.)
medium- A.kube-proxy
- B.kubelet
- C.container runtime
- ✓ D.kube-apiserver
- ✓ E.kube-scheduler
Why D: The kube-apiserver (option D) is the central control plane component that exposes the Kubernetes API, validating and processing all REST requests and serving as the front end for the cluster's shared state in etcd. The kube-scheduler (option E) is also a control plane component, responsible for watching for newly created Pods with no assigned node and selecting an appropriate node based on resource requirements, affinity rules, and other constraints. By contrast, kube-proxy (A) runs on each node and maintains network rules for Service traffic, the kubelet (B) is a node agent that ensures containers described in PodSpecs are running, and the container runtime (C) is the software on each node that actually runs containers — all three are node components, not control plane components.
Variation 2. Which TWO of the following components are part of the Kubernetes control plane? (Select 2)
medium- A.container runtime
- ✓ B.kube-apiserver
- C.kubelet
- ✓ D.etcd
- E.kube-proxy
Why B: The Kubernetes control plane consists of components that make global cluster decisions and store cluster state. Option B, kube-apiserver, is correct because it is the central management endpoint that exposes the Kubernetes API, validates and processes REST requests, and is the front end through which all other components communicate. Option D, etcd, is correct because it is the consistent, highly-available key-value store that persists all cluster data, including object specs and state, and is the backing store for the API server. The unmarked options are node-level components, not control plane components: the container runtime (A) executes containers on each node, kubelet (C) is the node agent that manages pods and containers on a node, and kube-proxy (E) implements Service networking rules on each node.
Variation 3. Which TWO of the following are Kubernetes control plane components?
medium- ✓ A.kube-apiserver
- B.container runtime
- ✓ C.etcd
- D.kube-proxy
- E.kubelet
Why A: kube-apiserver (A) is correct because it is the central control plane component that exposes the Kubernetes API, validating and processing all REST requests and serving as the front end of the control plane. etcd (C) is correct because it is the consistent, highly-available key-value store that persists all cluster state and is a core control plane component. The container runtime (B) is not a control plane component; it runs on each node as part of the kubelet's node-level machinery to execute containers. kube-proxy (D) is a node-level networking component that maintains network rules for Service traffic, not a control plane component. kubelet (E) is the node agent that manages pods on a worker node, so it is also not part of the control plane.
Variation 4. Which TWO of the following are control plane components? (Select TWO)
medium- ✓ A.etcd
- ✓ B.kube-apiserver
- C.kube-proxy
- D.kubelet
- E.Container runtime
Why A: In Kubernetes, the control plane is the set of components that make global cluster decisions and store cluster state, and etcd (A) is correct because it is the consistent, highly-available key-value store that persists all cluster data, including objects, configuration, and state. The kube-apiserver (B) is also correct because it is the central control plane component that exposes the Kubernetes API, validates and processes REST requests, and is the only component that talks directly to etcd. By contrast, kube-proxy (C) runs on each node and implements Service networking rules via iptables/IPVS, kubelet (D) is the node agent that manages Pods and containers on a worker node, and the container runtime (E) is the node-level software (e.g., containerd, CRI-O) that actually runs containers — all three are node components, not control plane components.
Variation 5. Which two components are part of the Kubernetes control plane? (Select TWO.)
medium- ✓ A.kube-apiserver
- B.container runtime
- C.kube-proxy
- D.kubelet
- ✓ E.etcd
Why A: The Kubernetes control plane is the set of components that make global cluster decisions and store cluster state, and it includes the kube-apiserver (A) and etcd (E). The kube-apiserver (A) is the front end of the control plane: it exposes the Kubernetes API, validates and processes REST requests, and is the only component that talks directly to etcd. etcd (E) is the consistent, highly available key-value store that persists all cluster data, including object definitions and state, making it a core control-plane component. The other options are node-level components, not control-plane components: the container runtime (B) and kubelet (D) run on each worker node to execute and manage pods, and kube-proxy (C) runs on each node to implement Service networking via iptables/IPVS rules.
Variation 6. Which two components are part of the Kubernetes control plane? (Select two.)
medium- ✓ A.etcd
- B.kube-proxy
- ✓ C.kube-apiserver
- D.kubelet
- E.container runtime
Why A: etcd (A) is correct because it is the control plane's distributed key-value store that persists all cluster state and configuration data, and kube-apiserver (C) is correct because it is the control plane component that exposes the Kubernetes API and serves as the front end through which all other components communicate. The other options are node-level components, not control plane components: kube-proxy (B) maintains network rules for Service traffic on each node, kubelet (D) runs on each node to manage Pods and containers, and the container runtime (E) is the software on each node that actually runs containers.
Variation 7. Which three components are part of the Kubernetes control plane?
hard- ✓ A.kube-controller-manager
- B.kube-proxy
- ✓ C.kube-scheduler
- ✓ D.kube-apiserver
- E.kubelet
Why A: The Kubernetes control plane consists of the components that make global cluster decisions and expose the cluster API. Option D, kube-apiserver, is correct because it is the front end of the control plane, serving the Kubernetes API over HTTPS and persisting cluster state in etcd. Option C, kube-scheduler, is correct because it watches for newly created Pods with no assigned node and selects a node for them based on resource requirements, affinity, and taints/tolerations. Option A, kube-controller-manager, is correct because it runs the built-in controller loops (such as node, replication, endpoints, and service account controllers) that drive the cluster toward its desired state. Option B, kube-proxy, is not part of the control plane; it is a node-level component that maintains network rules (iptables/IPVS) for Service load balancing. Option E, kubelet, is also not part of the control plane; it is the node agent that registers the node and manages Pod containers via the container runtime.
Variation 8. Which TWO components are part of the Kubernetes control plane?
easy- A.container runtime
- B.kubelet
- ✓ C.kube-apiserver
- ✓ D.etcd
- E.kube-proxy
Why C: The kube-apiserver (option C) is a core control-plane component: it exposes the Kubernetes API, validates and processes REST requests, and is the central communication hub that all other components (including kubelets and controllers) talk to. etcd (option D) is the control plane's consistent, highly-available key-value store that persists all cluster state and objects, making it an essential control-plane component. The container runtime (option A) is node-level software (e.g., containerd or CRI-O) that actually runs containers, not part of the control plane. The kubelet (option B) is a node agent that registers the node and manages pods on that node, so it resides on worker/control nodes as a node component rather than the control plane. kube-proxy (option E) is a node-level network proxy implementing Service rules via iptables/IPVS, and is likewise not a control-plane component.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.