KCNA Kubernetes Fundamentals Practice Question
Which THREE of the following are core components of a Kubernetes worker node?
⚠ Common exam trap
Many candidates confuse control plane components (etcd, kube-apiserver) with worker node components, especially when they see them listed together in a question about cluster architecture.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
container runtime
The three core components of a Kubernetes worker node are the container runtime (C), kube-proxy (D), and kubelet (E). The container runtime (C) is required because it is the software (e.g., containerd, CRI-O) that actually pulls images and runs containers on the node. kubelet (E) is the primary node agent that registers the node with the control plane and manages Pods and their containers via the CRI. kube-proxy (D) implements the Service networking rules on the node, maintaining iptables/IPVS rules so that Service VIPs and load balancing work for Pods. Options A (etcd) and B (kube-apiserver) are not worker node components; they are control plane components, with etcd being the cluster's key-value datastore and kube-apiserver being the API front end.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
etcd
Why it's wrong here
etcd is the control plane's distributed key-value store, holding cluster state, and runs on control plane nodes, not worker nodes. It would be the right component to name when asked about the control plane's data store or quorum sizing, not about what executes pods.
- ✗
kube-apiserver
Why it's wrong here
kube-apiserver is the control plane's front-end REST endpoint and runs on control plane nodes, not worker nodes. It is the correct answer when asked which component validates and processes API requests or mediates all cluster communication, rather than which components run on a worker.
- ✓
container runtime
Why this is correct
The container runtime runs on every worker node, pulling images and executing containers on behalf of the kubelet. This satisfies the worker node component requirement, distinguishing it from control plane components such as the API server that never execute workloads.
- ✓
kube-proxy
Why this is correct
kube-proxy runs on every worker node, programming iptables or IPVS rules so that Service virtual IPs route to the correct backend pods. This satisfies the stem's requirement for a core node component, since it implements the Service networking layer that lets cluster-internal traffic reach workloads.
- ✓
kubelet
Why this is correct
The kubelet is the node agent that watches PodSpecs from the API server and ensures their containers run and stay healthy. This satisfies the worker node component requirement, distinguishing it from control plane components such as the scheduler.
Go deeper
Related to this question
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on KCNA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which two components are part of the Kubernetes worker node? (Select TWO)
medium- ✓ A.kubelet
- B.kube-controller-manager
- C.etcd
- D.kube-scheduler
- ✓ E.container runtime
Why A: The kubelet (A) is correct because it is the primary node agent that runs on every worker node, registering the node with the API server and ensuring containers described in PodSpecs are running and healthy. The container runtime (E) is correct because the worker node needs a CRI-compliant runtime such as containerd or CRI-O to actually pull images and run containers. The kube-controller-manager (B), etcd (C), and kube-scheduler (D) are all control plane components that typically run on master nodes, not on worker nodes, so they are not part of the worker node.
Variation 2. Which TWO components are part of a Kubernetes worker node?
easy- ✓ A.kubelet
- B.kube-scheduler
- C.container runtime
- ✓ D.kube-proxy
- E.etcd
Why A: Option A, kubelet, is correct because the kubelet is the primary node agent that runs on every worker node, registering the node with the API server and ensuring containers described in PodSpecs are running and healthy. Option D, kube-proxy, is correct because it runs on each worker node to maintain network rules (via iptables/IPVS) that implement Kubernetes Service abstraction and enable pod-to-pod and external communication. Option B, kube-scheduler, is incorrect because it is a control plane component that assigns pods to nodes rather than running on worker nodes. Option C, container runtime, is not marked correct here even though a runtime such as containerd or CRI-O does run on worker nodes; per the given answer key it is excluded. Option E, etcd, is incorrect because it is the control plane's distributed key-value store for cluster state, not a worker node component.
Variation 3. Which TWO components are part of the Kubernetes worker node?
easy- A.kube-apiserver
- B.etcd
- C.kube-scheduler
- ✓ D.kube-proxy
- ✓ E.kubelet
Why D: kube-proxy (D) is a worker-node component that maintains network rules on each node to implement the Kubernetes Service abstraction, handling traffic forwarding via iptables/IPVS so Pods can reach Services. kubelet (E) is the primary node agent that runs on every worker node, registering the node with the control plane and managing Pod lifecycle by communicating with the container runtime via CRI. The other options belong to the control plane, not worker nodes: kube-apiserver (A) exposes the Kubernetes REST API and is the front end of the control plane, etcd (B) is the distributed key-value store holding cluster state, and kube-scheduler (C) assigns Pods to nodes from the control plane.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.