KCNA Kubernetes Fundamentals Practice Question
Which TWO components are part of the Kubernetes control plane?
⚠ Common exam trap
The KCNA exam often tests the misconception that kubelet or kube-proxy are control plane components because they are essential for cluster operation, but they actually run on every node as part of the data plane.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
etcd
etcd (C) is correct because it is the control plane's distributed key-value store that persistently holds all cluster state and configuration data, which the API server reads and writes. kube-apiserver (D) is correct because it is the central control plane component that exposes the Kubernetes API, validates and processes REST requests, and is the front end through which all other components communicate. The other options are node-level components, not control plane components: kube-proxy (A) implements Service networking rules on each node, kubelet (B) runs on each node and manages Pods/containers via the container runtime, and the container runtime (E) is the node software (e.g., containerd, CRI-O) that actually runs containers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kube-proxy
Why it's wrong here
kube-proxy implements Service networking rules on each node via iptables or IPVS, so it belongs to the node layer rather than the control plane. It is tempting because it is a fundamental cluster component, and it would be correct if the question asked which component maintains Service routing on worker nodes.
- ✗
kubelet
Why it's wrong here
The kubelet is a node agent that runs on every worker node, registering the node and managing pod lifecycles locally; it never runs as part of the control plane. It is tempting because it is a core Kubernetes component, and it would be the right answer to a question asking which component runs on each worker node.
- ✓
etcd
Why this is correct
etcd is the control plane's distributed key-value store, holding all cluster state and configuration. It satisfies the control plane membership criterion because it runs on control plane nodes alongside the API server, scheduler and controller manager, rather than on worker nodes with kubelet and kube-proxy.
- ✓
kube-apiserver
Why this is correct
kube-apiserver is the control plane's front end, exposing the Kubernetes API and validating every request before persisting state to etcd. It satisfies the control plane membership criterion because it runs on control plane nodes, unlike kubelet and kube-proxy, which run on every worker node.
- ✗
container runtime
Why it's wrong here
The container runtime runs on each worker node to start and stop containers, so it sits outside the control plane. It is tempting because it is essential cluster software, and would be the right answer if the question asked for node components instead.
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.