Courseiva
Kubernetes Fundamentals →easyMultiple Select

KCNA Kubernetes Fundamentals Practice Question

Which TWO components are part of the Kubernetes worker node?

⚠ Common exam trap

In the CNCF Kubernetes exam (e.g., KCNA), the distinction between control-plane and worker-node components is often tested. Candidates may confuse kube-scheduler or kube-apiserver as worker-node components because they are essential to cluster operation but run only on the control plane.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kube-proxy

kube-proxy (D) is a worker-node component that maintains network rules on each node to implement the Kubernetes Service abstraction, handling traffic forwarding via iptables/IPVS so Pods can reach Services. kubelet (E) is the primary node agent that runs on every worker node, registering the node with the control plane and managing Pod lifecycle by communicating with the container runtime via CRI. The other options belong to the control plane, not worker nodes: kube-apiserver (A) exposes the Kubernetes REST API and is the front end of the control plane, etcd (B) is the distributed key-value store holding cluster state, and kube-scheduler (C) assigns Pods to nodes from the control plane.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kube-apiserver

    Why it's wrong here

    kube-apiserver is the control plane's front-end exposing the Kubernetes API, not a worker node component. It is tempting because kubelet on each node communicates with it, but the apiserver runs on control plane hosts; worker nodes host kubelet, kube-proxy and the container runtime.

  • ✗

    etcd

    Why it's wrong here

    etcd is the control plane's distributed key-value store holding cluster state, not a worker node component. It is tempting because every node interacts with cluster state, but etcd runs alongside the kube-apiserver on control plane hosts, while worker nodes run kubelet and kube-proxy.

  • ✗

    kube-scheduler

    Why it's wrong here

    kube-scheduler runs on the control plane, assigning pods to nodes; it is not a worker node component. It is tempting because scheduling concerns nodes, but the worker node itself runs kubelet, kube-proxy and the container runtime, which execute and network the scheduled pods.

  • ✓

    kube-proxy

    Why this is correct

    Kube-proxy runs on every worker node, maintaining network rules that implement Kubernetes Service abstraction, enabling pod-to-pod and external traffic routing. It satisfies the worker node component requirement directly, alongside kubelet and the container runtime, distinguishing node-level networking from control plane functions such as scheduling.

  • ✓

    kubelet

    Why this is correct

    The kubelet is the node agent that runs on every worker node, registering the node with the control plane and ensuring containers described in PodSpecs are running and healthy. It satisfies the worker-node constraint because it operates on nodes, not the control plane.

Go deeper

Related to this question

About these practice questions

This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.