SaveMyCert
Log in
5 of 5 free questions left today·for 30 a day
KCNA · Domain 1

Kubernetes Fundamentals practice questions

Kubernetes Fundamentals is worth 44% of the KCNA exam — the heaviest of the 4 domains. The Kubernetes object model, cluster administration, scheduling, and containerization. Official weighting 44%. 6 fully worked examples are further down this page, answers included.

Exam weight
44%
the heaviest of the 4 domains
Questions
80
across 4 topics
Free, no account
5/day
sign up free to remove the cap
Explanations
Every option
right and wrong

Build a practice session

5 free questions left today.

Domains

How many?

Mode

Ready when you are

10 fresh questions drawn across 1 of 4 domains, in Learn mode.

Focused review

Every question you answer incorrectly, and every question you flag while practising, is saved here automatically. Finish a session and you can come back to re-drill just those.

6 sample Kubernetes Fundamentals questions, fully explained

Questions from the KCNA bank mapped to domain 1, with the answer key and the reasoning behind every option. None of them repeat the examples on the main KCNA practice page.

Question 1Kubernetes Fundamentals

Which Kubernetes component is the only one that reads from and writes to etcd directly?

Choose one.

  • a
    kubelet

    The kubelet reports Pod and node status to the kube-apiserver over the API. It has no direct access to etcd.

  • b
    kube-controller-manager

    Controllers watch and update objects through the kube-apiserver. They never open a connection to etcd themselves.

  • c
    kube-proxy

    kube-proxy watches Service and endpoint information via the API server to program network rules. It does not talk to etcd.

  • d
    kube-apiserver Correct

    By design, the kube-apiserver is the only component with a direct connection to etcd. All other components read and write cluster state through the API server.

The concept

etcd is the cluster's source of truth, but access to it is deliberately funneled through a single component: the kube-apiserver.

Why that’s the answer

Centralizing etcd access in the API server means authentication, authorization, admission control, and validation happen in exactly one place before any state changes. The controller manager and kubelet are plausible distractors because they constantly read and update state, but they always do so via API requests - if they wrote to etcd directly, they would bypass every security and validation layer.

How to reason it out
  1. A component or user submits a change through the Kubernetes API.
  2. The kube-apiserver validates the request and authorizes the caller.
  3. The kube-apiserver alone persists the resulting object into etcd.

Exam tip: Only kube-apiserver talks to etcd - every other component goes through the API server.

Kubernetes Core Concepts: Architecture, Pods, Deployments, and Services — the lesson that teaches this.

Question 2Kubernetes Fundamentals

What role does etcd play in a Kubernetes cluster?

Choose one.

  • a
    It runs the containers for control plane workloads

    Containers are run by the container runtime under the kubelet's direction. etcd stores data; it does not execute workloads.

  • b
    It is a distributed key-value store holding the cluster's state and configuration Correct

    etcd is a consistent, distributed key-value database. Every Kubernetes object - Pods, Services, ConfigMaps, and more - is persisted there, making it the cluster's source of truth.

  • c
    It load balances traffic between Pods

    Traffic distribution to Pods is handled by Services together with kube-proxy's network rules, not by etcd.

  • d
    It decides which node each Pod should run on

    Node selection is the job of kube-scheduler. etcd merely stores the resulting assignment as part of the Pod object.

The concept

etcd is the consistent, highly available key-value datastore that backs all Kubernetes cluster data - the definitive record of the cluster's desired and observed state.

Why that’s the answer

Every API object lives in etcd, which is why losing etcd without a backup means losing the cluster's state. The distractors assign etcd active behaviors - running containers, balancing traffic, scheduling - but etcd is purely a datastore: the scheduler, kube-proxy, and the container runtime perform those actions, and etcd just records the outcomes via the API server.

How to reason it out
  1. The kube-apiserver writes every created or updated object into etcd.
  2. Controllers and the scheduler read that state (through the API server) to make decisions.
  3. Because etcd holds the source of truth, backing it up is how you back up the cluster.

Exam tip: etcd is the cluster's key-value source of truth - it stores state, and only the API server accesses it.

Kubernetes Core Concepts: Architecture, Pods, Deployments, and Services — the lesson that teaches this.

Question 3Kubernetes Fundamentals

What is the responsibility of kube-scheduler?

Choose one.

  • a
    It starts the Pod's containers on the chosen node

    Starting containers is the kubelet's job, done through the container runtime. The scheduler only decides where the Pod should run.

  • b
    It stores the cluster's configuration data

    Cluster state is stored in etcd, behind the kube-apiserver. The scheduler holds no persistent state of its own.

  • c
    It selects a suitable node for each newly created Pod that has no node assigned Correct

    The scheduler watches for Pods without a node assignment, filters and scores the available nodes, and records its choice on the Pod. That is its entire job.

  • d
    It restarts containers that crash on a node

    Restarting crashed containers is handled locally by the kubelet according to the Pod's restart policy, not by the scheduler.

The concept

kube-scheduler has one narrow responsibility: assigning unscheduled Pods to nodes based on resource requirements, constraints, and policies.

Why that’s the answer

Scheduling is a decision, not an action. The scheduler picks the node and writes that binding to the Pod via the API server - then its involvement ends. The tempting distractor is starting containers: many assume the scheduler places and launches Pods, but the kubelet on the chosen node notices the assignment and does the launching. Crash restarts are likewise the kubelet's local responsibility.

How to reason it out
  1. A new Pod is created and has no node assigned.
  2. kube-scheduler filters out unsuitable nodes and scores the remaining candidates.
  3. It binds the Pod to the best node, and that node's kubelet then starts the containers.

Exam tip: The scheduler only picks the node - the kubelet on that node actually starts the containers.

Kubernetes Core Concepts: Architecture, Pods, Deployments, and Services — the lesson that teaches this.

Question 4Kubernetes Fundamentals

Which component runs on every node and makes sure the containers described in each Pod assigned to that node are actually running, by instructing the container runtime?

Choose one.

  • a
    kube-controller-manager

    The controller manager runs cluster-level control loops on the control plane. It does not run on every node or talk to the container runtime.

  • b
    kube-proxy

    kube-proxy also runs on every node, but it manages network rules for Services. It never starts or manages containers.

  • c
    etcd

    etcd is the control plane's datastore. It stores Pod definitions but plays no part in running containers on nodes.

  • d
    kubelet Correct

    The kubelet is the node agent. It watches for Pods assigned to its node and drives the container runtime to start, monitor, and restart their containers.

The concept

The kubelet is the primary node agent in Kubernetes: it turns Pod specifications into running containers by working with a container runtime (via the Container Runtime Interface).

Why that’s the answer

Once the scheduler assigns a Pod to a node, that node's kubelet takes over - pulling images, starting containers through the runtime, running health probes, and reporting status back to the API server. kube-proxy is the classic distractor since it also runs on every node, but its domain is Service networking, not container lifecycle.

How to reason it out
  1. The kubelet sees (via the API server) that a Pod has been assigned to its node.
  2. It instructs the container runtime to pull images and start the Pod's containers.
  3. It continuously monitors the containers and reports Pod status back to the API server.

Exam tip: kubelet is the per-node agent that makes Pods real by driving the container runtime.

Kubernetes Core Concepts: Architecture, Pods, Deployments, and Services — the lesson that teaches this.

Question 5Kubernetes Fundamentals

What is the primary job of kube-proxy?

Choose one.

  • a
    It proxies kubectl commands from users to the control plane

    kubectl talks directly to the kube-apiserver over HTTPS. Despite the name, kube-proxy has nothing to do with forwarding client API requests.

  • b
    It assigns IP addresses to newly created Pods

    Pod IP assignment is handled by the cluster's container network plugin (CNI), not by kube-proxy.

  • c
    It maintains network rules on each node so traffic sent to a Service reaches one of its backend Pods Correct

    kube-proxy watches Services and their endpoints and programs the node's networking (for example iptables or IPVS rules) so Service traffic is forwarded to healthy backend Pods.

  • d
    It schedules Pods across nodes to balance load

    Placing Pods on nodes is kube-scheduler's job. kube-proxy only handles traffic to Services after the Pods are running.

The concept

kube-proxy runs on every node and implements the Service abstraction at the network level, keeping forwarding rules in sync with the cluster's Services and endpoints.

Why that’s the answer

When a client sends traffic to a Service's virtual IP, something must translate that into a real Pod IP - that is kube-proxy's rule set at work. The name misleads people into the kubectl-proxying distractor, but kube-proxy never touches API traffic; and Pod IPs come from the CNI plugin, while node placement comes from the scheduler.

How to reason it out
  1. kube-proxy watches the API server for Services and their endpoint Pods.
  2. It programs the node's packet forwarding rules (iptables, IPVS, or similar).
  3. Traffic addressed to a Service IP is then redirected to one of the healthy backend Pods.

Exam tip: kube-proxy makes Service virtual IPs work by programming per-node network forwarding rules.

Kubernetes Core Concepts: Architecture, Pods, Deployments, and Services — the lesson that teaches this.

Question 6Kubernetes Fundamentals

What does the kube-controller-manager do?

Choose one.

  • a
    It manages the etcd database cluster

    etcd is operated as its own component (or external cluster). The controller manager neither runs nor administers etcd.

  • b
    It runs the control loops (such as the ReplicaSet and node controllers) that watch cluster state and drive it toward the desired state Correct

    The controller manager hosts Kubernetes' built-in controllers. Each controller compares desired state to observed state and takes corrective action through the API server.

  • c
    It provides the command line interface for cluster administrators

    The administrator CLI is kubectl, a separate client program. The controller manager is a server-side control plane process.

  • d
    It serves container images to the nodes

    Container images come from image registries and are pulled by the container runtime on each node. The controller manager is not involved in image distribution.

The concept

kube-controller-manager is the control plane process that bundles Kubernetes' core controllers - independent reconciliation loops like the ReplicaSet, node, and endpoints controllers.

Why that’s the answer

Controllers are what make Kubernetes declarative: each one watches a slice of the cluster and continuously nudges reality toward what the user asked for. For example, the ReplicaSet controller creates or deletes Pods when the actual count drifts from the requested count. The distractors describe real cluster concerns - etcd operation, the CLI, image delivery - but each belongs to etcd itself, kubectl, and registries plus the runtime respectively.

How to reason it out
  1. Each controller watches the API server for the objects it is responsible for.
  2. It compares the object's desired state with the cluster's observed state.
  3. When they differ, it issues API requests (create, update, delete) to converge them.

Exam tip: kube-controller-manager runs the reconciliation loops that continuously push actual state toward desired state.

Kubernetes Core Concepts: Architecture, Pods, Deployments, and Services — the lesson that teaches this.

What KCNA domain 1 tests, topic by topic

The official exam guide breaks Kubernetes Fundamentals into 4 topics. The question bank follows the same split, so a weak topic shows up as a cluster of misses you can go back and read.

Published KCNA practice questions per topic in Kubernetes Fundamentals
TopicWhat it coversQuestions
Kubernetes Core ConceptsOfficial KCNA competency (Kubernetes Fundamentals). The Kubernetes architecture and object model: control plane vs worker nodes, the API server and etcd, controllers and desired-state reconciliation, and the core resources (Pods, ReplicaSets, Deployments, Services, namespaces) with declarative configuration.20
AdministrationOfficial KCNA competency. Managing a Kubernetes cluster: kubectl and the API, the cluster components (kube-apiserver, kube-scheduler, kube-controller-manager, kubelet, kube-proxy), role-based access control (RBAC) basics, namespaces, and resource quotas.20
SchedulingOfficial KCNA competency. How the scheduler places Pods onto nodes: resource requests and limits, node selectors, affinity and anti-affinity, taints and tolerations, and scheduling constraints.20
ContainerizationOfficial KCNA competency. Container fundamentals underpinning Kubernetes: images and registries, container runtimes and the Container Runtime Interface (CRI), Open Container Initiative (OCI) standards, and building and running containers.20
Total80

Revise Kubernetes Fundamentals before you drill it

Other KCNA domains

Kubernetes Fundamentals: your questions

Kubernetes Fundamentals is domain 1 of the KCNA exam guide and carries 44% of the scored content — the heaviest of the 4 domains. On a 60-question paper that works out to roughly 26 questions, though CNCF does not publish an exact per-domain count and individual exam forms vary.

Source

The domain weight and topic list on this page come from the official KCNA exam guide.