KCNA Kubernetes Fundamentals Practice Question
Which TWO statements correctly describe the purpose of etcd in a Kubernetes cluster?
⚠ Common exam trap
CNCF often tests the distinction between the component that stores state (etcd) and the components that use that state (scheduler, controller manager, API server), so the trap here is confusing etcd's role as a passive data store with the active management functions of other control plane components.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It stores the cluster state, including all Kubernetes objects.
Option A is correct because etcd is the backing store for all Kubernetes cluster data: every API object (Pods, Services, ConfigMaps, Secrets, etc.) is serialized and persisted in etcd, making it the single source of truth for cluster state. Option E is correct because etcd is fundamentally a distributed key-value store built on the Raft consensus algorithm, which replicates data across members to deliver high availability and strong consistency (linearizable reads/writes). Option B is wrong because Pod-to-Pod network rules are implemented by the CNI plugin and kube-proxy (iptables/IPVS or eBPF), not etcd. Option C is wrong because Pod scheduling is the job of kube-scheduler, which watches the API server and binds Pods to nodes. Option D is wrong because the Kubernetes API is exposed by kube-apiserver; etcd only serves as its storage backend and is not itself an API endpoint for clients.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It stores the cluster state, including all Kubernetes objects.
Why this is correct
etcd is the cluster's sole source of truth, persisting the entire state of every Kubernetes object — Pods, Services, Deployments, ConfigMaps and more. The API server reads and writes all object data exclusively through etcd, making this storage role fundamental.
- ✗
It manages network rules for Pod-to-Pod communication.
Why it's wrong here
etcd is the cluster's consistent key-value store, persisting all API objects and state; network rules for Pod-to-Pod traffic are enforced by CNI plugins and NetworkPolicy, not etcd. It is tempting because etcd does store NetworkPolicy objects, but its role is storage, not enforcement of connectivity.
- ✗
It schedules Pods onto nodes based on resource availability.
Why it's wrong here
Pod placement is performed by the kube-scheduler, which watches for unscheduled Pods and binds them to nodes; etcd merely stores the resulting bindings. The confusion arises because etcd holds node and Pod specifications, but it never evaluates resource availability or makes scheduling decisions.
- ✗
It exposes the Kubernetes API for external access.
Why it's wrong here
The Kubernetes API is exposed by kube-apiserver, which serves REST requests and authenticates clients; etcd is only its backing datastore, reached by the apiserver rather than by external users. It is tempting because etcd underpins every API object, yet it offers no API surface itself.
- ✓
It is a distributed key-value store that provides high availability and consistency.
Why this is correct
etcd is a distributed key-value store built on the Raft consensus algorithm, which replicates writes across cluster members to guarantee consistency and high availability. This lets a Kubernetes control plane survive individual etcd member failures without losing or corrupting cluster state.
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.