Courseiva
Kubernetes Fundamentals →mediumMultiple Select

KCNA Kubernetes Fundamentals Practice Question

Which two components are part of the Kubernetes control plane? (Select two.)

⚠ Common exam trap

A common trap is confusing control plane components (etcd, kube-apiserver, kube-controller-manager, kube-scheduler) with node-level components like kubelet, kube-proxy, and the container runtime. Candidates often select kube-proxy or kubelet, which run on every node, instead of the centralized control plane services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

etcd

etcd (A) is correct because it is the control plane's distributed key-value store that persists all cluster state and configuration data, and kube-apiserver (C) is correct because it is the control plane component that exposes the Kubernetes API and serves as the front end through which all other components communicate. The other options are node-level components, not control plane components: kube-proxy (B) maintains network rules for Service traffic on each node, kubelet (D) runs on each node to manage Pods and containers, and the container runtime (E) is the software on each node that actually runs containers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    etcd

    Why this is correct

    etcd is the control plane's distributed key-value store, holding all cluster state and configuration. The API server reads and writes exclusively to it, making etcd a core control plane component rather than a node-level one.

  • ✗

    kube-proxy

    Why it's wrong here

    kube-proxy runs on each worker node, implementing Service networking via iptables or IPVS rules; it is a node component, not control plane. The control plane comprises kube-apiserver, etcd, kube-scheduler and kube-controller-manager. kube-proxy tempts because it is central to cluster networking, yet it executes on nodes.

  • ✓

    kube-apiserver

    Why this is correct

    The kube-apiserver is a core control plane component, exposing the Kubernetes API that every cluster operation flows through. It validates and processes REST requests, then persists state to etcd, satisfying the stem's requirement for control plane membership. Worker-node components such as kubelet and kube-proxy are excluded, confirming this selection.

  • ✗

    kubelet

    Why it's wrong here

    The kubelet runs on each worker node, registering the node and managing pod lifecycles locally, so it sits outside the control plane. It is tempting because it is a core Kubernetes component and appears in every cluster, but it would be the correct answer only when asked which components run on worker nodes.

  • ✗

    container runtime

    Why it's wrong here

    The container runtime (containerd, CRI-O) executes on every worker node to run pods; it is a node component, not control plane. Control plane components are kube-apiserver, etcd, kube-scheduler and kube-controller-manager. The runtime tempts because Kubernetes orchestrates containers, but orchestration logic resides in the control plane.

About these practice questions

This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.