Courseiva
Kubernetes Fundamentals →mediumMultiple Select

KCNA Kubernetes Fundamentals Practice Question

Which THREE of the following are core components of a Kubernetes worker node?

⚠ Common exam trap

Many candidates confuse control plane components (etcd, kube-apiserver) with worker node components, especially when they see them listed together in a question about cluster architecture.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

container runtime

The three core components of a Kubernetes worker node are the container runtime (C), kube-proxy (D), and kubelet (E). The container runtime (C) is required because it is the software (e.g., containerd, CRI-O) that actually pulls images and runs containers on the node. kubelet (E) is the primary node agent that registers the node with the control plane and manages Pods and their containers via the CRI. kube-proxy (D) implements the Service networking rules on the node, maintaining iptables/IPVS rules so that Service VIPs and load balancing work for Pods. Options A (etcd) and B (kube-apiserver) are not worker node components; they are control plane components, with etcd being the cluster's key-value datastore and kube-apiserver being the API front end.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    etcd

    Why it's wrong here

    etcd is the control plane's distributed key-value store, holding cluster state, and runs on control plane nodes, not worker nodes. It would be the right component to name when asked about the control plane's data store or quorum sizing, not about what executes pods.

  • ✗

    kube-apiserver

    Why it's wrong here

    kube-apiserver is the control plane's front-end REST endpoint and runs on control plane nodes, not worker nodes. It is the correct answer when asked which component validates and processes API requests or mediates all cluster communication, rather than which components run on a worker.

  • ✓

    container runtime

    Why this is correct

    The container runtime runs on every worker node, pulling images and executing containers on behalf of the kubelet. This satisfies the worker node component requirement, distinguishing it from control plane components such as the API server that never execute workloads.

  • ✓

    kube-proxy

    Why this is correct

    kube-proxy runs on every worker node, programming iptables or IPVS rules so that Service virtual IPs route to the correct backend pods. This satisfies the stem's requirement for a core node component, since it implements the Service networking layer that lets cluster-internal traffic reach workloads.

  • ✓

    kubelet

    Why this is correct

    The kubelet is the node agent that watches PodSpecs from the API server and ensures their containers run and stay healthy. This satisfies the worker node component requirement, distinguishing it from control plane components such as the scheduler.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on KCNA

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which two components are part of the Kubernetes worker node? (Select TWO)

medium
  • ✓ A.kubelet
  • B.kube-controller-manager
  • C.etcd
  • D.kube-scheduler
  • ✓ E.container runtime

Why A: The kubelet (A) is correct because it is the primary node agent that runs on every worker node, registering the node with the API server and ensuring containers described in PodSpecs are running and healthy. The container runtime (E) is correct because the worker node needs a CRI-compliant runtime such as containerd or CRI-O to actually pull images and run containers. The kube-controller-manager (B), etcd (C), and kube-scheduler (D) are all control plane components that typically run on master nodes, not on worker nodes, so they are not part of the worker node.

Variation 2. Which TWO components are part of a Kubernetes worker node?

easy
  • ✓ A.kubelet
  • B.kube-scheduler
  • C.container runtime
  • ✓ D.kube-proxy
  • E.etcd

Why A: Option A, kubelet, is correct because the kubelet is the primary node agent that runs on every worker node, registering the node with the API server and ensuring containers described in PodSpecs are running and healthy. Option D, kube-proxy, is correct because it runs on each worker node to maintain network rules (via iptables/IPVS) that implement Kubernetes Service abstraction and enable pod-to-pod and external communication. Option B, kube-scheduler, is incorrect because it is a control plane component that assigns pods to nodes rather than running on worker nodes. Option C, container runtime, is not marked correct here even though a runtime such as containerd or CRI-O does run on worker nodes; per the given answer key it is excluded. Option E, etcd, is incorrect because it is the control plane's distributed key-value store for cluster state, not a worker node component.

Variation 3. Which TWO components are part of the Kubernetes worker node?

easy
  • A.kube-apiserver
  • B.etcd
  • C.kube-scheduler
  • ✓ D.kube-proxy
  • ✓ E.kubelet

Why D: kube-proxy (D) is a worker-node component that maintains network rules on each node to implement the Kubernetes Service abstraction, handling traffic forwarding via iptables/IPVS so Pods can reach Services. kubelet (E) is the primary node agent that runs on every worker node, registering the node with the control plane and managing Pod lifecycle by communicating with the container runtime via CRI. The other options belong to the control plane, not worker nodes: kube-apiserver (A) exposes the Kubernetes REST API and is the front end of the control plane, etcd (B) is the distributed key-value store holding cluster state, and kube-scheduler (C) assigns Pods to nodes from the control plane.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.