Courseiva
Kubernetes Fundamentals →mediumMultiple Select

KCNA Kubernetes Fundamentals Practice Question

Which two components are part of the Kubernetes worker node? (Choose two.)

⚠ Common exam trap

The trap in this question is that candidates often confuse control plane components (like kube-scheduler, kube-apiserver, etcd) with worker node components. Remember that kubelet and kube-proxy run on each worker node, while the scheduler, API server, and etcd run on the control plane.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kube-proxy

kube-proxy (A) is correct because it runs on every worker node and maintains the node's network rules (iptables/IPVS) that implement Kubernetes Service load balancing and ClusterIP/NodePort routing. kubelet (D) is correct because it is the primary node agent that registers the node with the API server, watches PodSpecs, and drives the container runtime (via CRI) to start, stop, and monitor containers and their volumes. The other components belong to the control plane: kube-scheduler (B) assigns Pods to nodes, etcd (C) is the cluster's distributed key-value datastore, and kube-apiserver (E) exposes the REST API and is the front end of the control plane, so none of them are worker node components.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    kube-proxy

    Why this is correct

    Kube-proxy runs on every worker node, implementing the Service abstraction by maintaining iptables or IPVS rules that route traffic to the correct pods. This satisfies the stem's requirement for a worker node component, since it handles node-local network programming rather than cluster-wide control-plane functions.

  • ✗

    kube-scheduler

    Why it's wrong here

    kube-scheduler is a control plane component that assigns unscheduled pods to nodes by evaluating resources and constraints; it does not run on worker nodes. It is tempting because scheduling decisions directly affect which node runs a pod, but the worker node only hosts kubelet, kube-proxy and the container runtime.

  • ✗

    etcd

    Why it's wrong here

    etcd is the control plane's distributed key-value store holding all cluster state; it runs alongside the API server on control plane nodes, not on workers. It is tempting because every worker depends on etcd indirectly through the API server, but worker nodes host only kubelet, kube-proxy and the container runtime.

  • ✓

    kubelet

    Why this is correct

    kubelet is the node agent that registers the node, watches PodSpecs from the API server, and starts containers via the container runtime. It satisfies the worker-node component requirement, unlike API server or etcd, which are control-plane.

  • ✗

    kube-apiserver

    Why it's wrong here

    kube-apiserver runs on control plane nodes, exposing the Kubernetes API that workers and clients call; it is never a worker node component. It is tempting because every node's kubelet communicates with it, but worker nodes host kubelet, kube-proxy and the container runtime, not the API server itself.

Go deeper

Related to this question

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.