Courseiva
Kubernetes Fundamentals →mediumMultiple Select

KCNA Kubernetes Fundamentals Practice Question

Which TWO components are part of the Kubernetes control plane? (Select exactly two.)

⚠ Common exam trap

CNCF often tests the distinction between control plane and worker node components, and the trap here is that candidates confuse kube-proxy or kubelet (which run on every node) with control plane components because they are essential for cluster operation, but they are not part of the control plane itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kube-apiserver

The kube-apiserver (option D) is the central control plane component that exposes the Kubernetes API, validating and processing all REST requests and serving as the front end for the cluster's shared state in etcd. The kube-scheduler (option E) is also a control plane component, responsible for watching for newly created Pods with no assigned node and selecting an appropriate node based on resource requirements, affinity rules, and other constraints. By contrast, kube-proxy (A) runs on each node and maintains network rules for Service traffic, the kubelet (B) is a node agent that ensures containers described in PodSpecs are running, and the container runtime (C) is the software on each node that actually runs containers — all three are node components, not control plane components.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kube-proxy

    Why it's wrong here

    kube-proxy runs on worker nodes, implementing Service networking rules via iptables or IPVS; it is absent from the control plane. It is tempting because it is essential cluster networking, but it is a node-level component, not one of the control plane processes.

  • ✗

    kubelet

    Why it's wrong here

    kubelet runs on each worker node, registering the node and managing pod lifecycle; it is not a control plane component. It is tempting because it is a core Kubernetes agent, but it belongs to the node's data plane alongside the container runtime and kube-proxy.

  • ✗

    container runtime

    Why it's wrong here

    The container runtime executes containers on worker nodes and is not part of the control plane. It is tempting because Kubernetes cannot run workloads without it, but it is a node component, sitting alongside kubelet and kube-proxy rather than the API server, scheduler, or controller manager.

  • ✓

    kube-apiserver

    Why this is correct

    kube-apiserver is the control plane's central REST front end: it validates and persists every object to etcd and is the only component all others talk to. It satisfies the control-plane criterion because it runs on the control plane, not on worker nodes.

  • ✓

    kube-scheduler

    Why this is correct

    kube-scheduler is a control-plane component that watches for newly created Pods with no assigned node and binds each to a suitable node based on resource requests, affinity and taints. It satisfies the control-plane criterion because it runs as part of the control plane, not on worker nodes.

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.