KCSA Kubernetes Cluster Component Security Practice Question
Which file on a Kubernetes control plane node contains the startup arguments and flags for the statically hosted API server?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/etc/kubernetes/manifests/kube-apiserver.yaml
Static pods for control plane components are defined in YAML files located in /etc/kubernetes/manifests.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
/etc/systemd/system/kube-apiserver.service
Why it's wrong here
In kubeadm-deployed clusters, core control plane components run as static pods, not systemd services.
- ✓
/etc/kubernetes/manifests/kube-apiserver.yaml
Why this is correct
The API server static pod manifest contains its container spec and command-line arguments.
- ✗
/etc/default/kube-apiserver
Why it's wrong here
Environment file conventions are typically used for package-based installations, not standard kubeadm manifests.
- ✗
/var/lib/kubelet/config.yaml
Why it's wrong here
This file configures the kubelet daemon, not the API server.
About these practice questions
Courseiva writes every KCSA question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official CNCF / Linux Foundation exam blueprint
This KCSA practice question is part of Courseiva's free CNCF / Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCSA exam.