KCNA Kubernetes Fundamentals Practice Question
Which TWO components run on every worker node in a Kubernetes cluster?
⚠ Common exam trap
CNCF often tests the distinction between control plane components and worker node components, trapping candidates who assume that all core Kubernetes components (like kube-scheduler or etcd) run on every node.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubelet
kubelet (B) is correct because it is the primary node agent that runs on every worker node, registering the node with the API server and managing pod lifecycles by ensuring containers described in PodSpecs are running and healthy. kube-proxy (D) is also correct because it runs on every worker node to maintain network rules (via iptables, IPVS, or nftables) that implement Kubernetes Service abstraction and enable pod-to-pod and external communication. In contrast, kube-scheduler (A), etcd (C), and kube-apiserver (E) are control plane components that typically run on master/control-plane nodes, not on every worker node, so they do not belong in this answer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kube-scheduler
Why it's wrong here
kube-scheduler runs on control plane nodes, not every worker node; it assigns pods to nodes cluster-wide. It is tempting because scheduling is essential to pod placement, but worker nodes instead run kubelet and kube-proxy, which handle pod execution and service networking locally.
- ✓
kubelet
Why this is correct
The kubelet runs as an agent on every worker node, receiving PodSpecs from the control plane and ensuring the described containers are running and healthy via the container runtime. It is a node-level, not control-plane, component.
- ✗
etcd
Why it's wrong here
etcd is the control plane's distributed key-value store holding cluster state, and it does not run on worker nodes. It is tempting because etcd is genuinely central to Kubernetes, storing all object data, but the components present on every worker node are kubelet and kube-proxy.
- ✓
kube-proxy
Why this is correct
Kube-proxy runs on every worker node, implementing Service virtual IPs by programming iptables or IPVS rules so pod traffic reaches the correct endpoints. This satisfies the stem's "every worker node" constraint, since it is a node-level DaemonSet component rather than a control-plane service.
- ✗
kube-apiserver
Why it's wrong here
kube-apiserver runs on control plane nodes, exposing the Kubernetes API; it is not present on worker nodes. It is tempting because every kubectl command and controller interacts with it, but worker nodes run kubelet and kube-proxy to execute pods and route service traffic.
Go deeper
Related to this question
Learn chapter
Cluster Architecture and Lifecycle Management
Key term
ReplicaSet and Replication
A ReplicaSet ensures a specified number of identical pod instances are running at all times in Kubernetes, using replication to maintain availability and stability.
Key term
Kubernetes API Primitives
Kubernetes API Primitives are the basic building blocks that the Kubernetes API uses to represent and manage the state of a cluster, such as Pods, Services, Deployments, and Namespaces.
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.