Courseiva
Kubernetes Fundamentals →mediumMultiple Select

KCNA Kubernetes Fundamentals Practice Question

Which TWO of the following components are part of the Kubernetes control plane? (Select 2)

⚠ Common exam trap

Candidates often confuse kubelet or kube-proxy (which run on every node) as part of the control plane because they are essential for cluster operation, but they are not control plane components.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kube-apiserver

The Kubernetes control plane consists of components that make global cluster decisions and store cluster state. Option B, kube-apiserver, is correct because it is the central management endpoint that exposes the Kubernetes API, validates and processes REST requests, and is the front end through which all other components communicate. Option D, etcd, is correct because it is the consistent, highly-available key-value store that persists all cluster data, including object specs and state, and is the backing store for the API server. The unmarked options are node-level components, not control plane components: the container runtime (A) executes containers on each node, kubelet (C) is the node agent that manages pods and containers on a node, and kube-proxy (E) implements Service networking rules on each node.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    container runtime

    Why it's wrong here

    The container runtime executes containers on each node via the CRI, so it is a worker node component, not control plane. It is tempting because the control plane schedules pods that the runtime then runs, but scheduling and execution are separate concerns.

  • ✓

    kube-apiserver

    Why this is correct

    kube-apiserver is the control plane component exposing the Kubernetes API; every kubectl request and internal component interaction flows through it, and it validates and persists objects to etcd. It is therefore part of the control plane.

  • ✗

    kubelet

    Why it's wrong here

    kubelet runs on every worker node, registering the node and managing pod lifecycles; it is not a control plane component. It is tempting because kubelet is essential to cluster operation and appears in control-plane discussions, and would be correct when listing node components alongside kube-proxy and the container runtime.

  • ✓

    etcd

    Why this is correct

    etcd is the control plane's consistent, highly-available key-value store, persisting all cluster state including object definitions, configuration and service discovery data. The API server reads and writes exclusively through it, making it essential to control plane operation. This satisfies the stem's requirement for a control plane component, unlike worker-node-only components such as kubelet or kube-proxy.

  • ✗

    kube-proxy

    Why it's wrong here

    kube-proxy runs on each node, implementing Service virtual IPs via iptables or IPVS rules; it is a node component, not control plane. It is tempting because it is central to cluster networking and is often listed alongside control plane services, but it belongs to the data plane.

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.