Courseiva
Kubernetes Fundamentals →mediumMultiple Select

KCNA Kubernetes Fundamentals Practice Question

Which TWO of the following are Kubernetes control plane components?

⚠ Common exam trap

CNCF often tests the distinction between control plane and worker node components, expecting candidates to mistakenly include kubelet or kube-proxy as control plane components because they are essential for cluster operation but run on nodes, not the control plane.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kube-apiserver

kube-apiserver (A) is correct because it is the central control plane component that exposes the Kubernetes API, validating and processing all REST requests and serving as the front end of the control plane. etcd (C) is correct because it is the consistent, highly-available key-value store that persists all cluster state and is a core control plane component. The container runtime (B) is not a control plane component; it runs on each node as part of the kubelet's node-level machinery to execute containers. kube-proxy (D) is a node-level networking component that maintains network rules for Service traffic, not a control plane component. kubelet (E) is the node agent that manages pods on a worker node, so it is also not part of the control plane.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    kube-apiserver

    Why this is correct

    The kube-apiserver is the control plane's front end, exposing the Kubernetes API that every other component and user interacts with. It validates and persists object state to etcd, so it runs on control plane nodes rather than worker nodes, satisfying the question's control plane component criterion.

  • ✗

    container runtime

    Why it's wrong here

    The container runtime executes containers on worker nodes via the CRI, so it is a node component rather than a control plane component. It is tempting because Kubernetes cannot run workloads without it, but it would be correct only when the question asks which components run on each node.

  • ✓

    etcd

    Why this is correct

    etcd is the distributed key-value store holding all cluster state, including every object definition and configuration. The kube-apiserver reads and writes to it exclusively, making it a core control plane component rather than a node-level workload such as kubelet or kube-proxy.

  • ✗

    kube-proxy

    Why it's wrong here

    kube-proxy runs on each node as part of the data plane, implementing Service load balancing through iptables or IPVS rules. It would be correct only when listing node components, not control plane components such as kube-apiserver, etcd, kube-scheduler and kube-controller-manager.

  • ✗

    kubelet

    Why it's wrong here

    kubelet runs on each worker node, registering the node and managing pod lifecycles locally, so it sits outside the control plane. It is tempting because it is a core Kubernetes component and appears in every cluster, but it would be the right answer only when asked for node components rather than control plane components.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.