Courseiva
Kubernetes Fundamentals →mediumMultiple Select

KCNA Kubernetes Fundamentals Practice Question

Which TWO of the following are responsibilities of the kube-controller-manager?

⚠ Common exam trap

A common mix-up: candidates confuse the kube-controller-manager's role in node health monitoring with the kube-scheduler's role in pod placement, or they mistakenly think the controller-manager handles network rules, which is actually done by kube-proxy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensuring the correct number of pod replicas are running

Option B is correct because the kube-controller-manager runs the ReplicationController/ReplicaSet controller, which continuously reconciles the desired replica count in a workload's spec with the actual number of running pods, creating or deleting pods as needed. Option D is correct because the kube-controller-manager includes the node controller, which monitors node heartbeats/status and reacts to node failures by marking nodes NotReady and evicting or rescheduling their pods (subject to tolerations). Option A is not a kube-controller-manager responsibility; pod-to-node assignment is performed by the kube-scheduler. Option C is not correct because Service network rules are implemented by the kube-proxy component (and/or CNI/iptables/IPVS), not the kube-controller-manager. Option E is not correct because cluster state is stored in etcd, the distributed key-value store, not by the kube-controller-manager.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Assigning pods to nodes based on resource requirements

    Why it's wrong here

    Pod-to-node assignment is the kube-scheduler's job, which watches for unscheduled pods and binds them using resource requests, affinity and taints. The kube-controller-manager runs reconciliation loops such as node, replication and endpoints controllers. Confusing scheduling with control loops is the trap here.

  • ✓

    Ensuring the correct number of pod replicas are running

    Why this is correct

    The kube-controller-manager runs the ReplicaSet controller, which continuously reconciles the observed replica count against the desired count declared in the ReplicaSet spec, creating or deleting pods to close any gap. This directly satisfies the stem's requirement to maintain the correct number of running pod replicas.

  • ✗

    Implementing network rules for Services

    Why it's wrong here

    Service network rules are programmed by kube-proxy, which writes iptables or IPVS rules on each node; the kube-controller-manager instead runs reconciliation loops such as ReplicaSet and EndpointSlice controllers. It is tempting because the controller manager does create EndpointSlices for Services, but translating those endpoints into packet-forwarding rules is kube-proxy's job.

  • ✓

    Monitoring node health and responding to node failures

    Why this is correct

    The node lifecycle controller within the kube-controller-manager watches node status; on missed heartbeats it marks nodes NotReady and evicts their Pods, triggering rescheduling. This satisfies the requirement to monitor node health and respond to failures.

  • ✗

    Storing the cluster state

    Why it's wrong here

    Cluster state persists in etcd, the distributed key-value store that the API server alone reads and writes; the kube-controller-manager only watches the API server and reconciles controllers such as Deployment and Node. It is tempting because controller managers do cache objects locally, but that cache is transient, not the authoritative store.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.