- Home
- All questions
- Services
CKA study material: Services
125 questions of the 1000 in the CKA — Certified Kubernetes Administrator quiz. Each opens with its answer, the reasoning and where that is written down.
Challenge yourself on this topic → Study as cards
The questions
- 7. Which controller populates the objects that link a Service to the Pods behind it?
- 201. A Service manifest sets port 80 but omits targetPort. Which port on the Pod receives traffic?
- 202. Why would an administrator use a named targetPort instead of a number?
- 203. A Service is created with no selector. Which two statements are correct? Choose two.
- 204. Which Service type is used when none is specified?
- 205. What does a NodePort Service do? Choose two.
- 206. What is the default port range for NodePort Services?
- 207. An administrator sets a nodePort explicitly. Which two responsibilities does that create? Choose two.
- 208. Where does a LoadBalancer Service report the address the cloud provider assigned?
- 209. Which Service type performs no proxying and simply resolves to another DNS name?
- 210. What is true of a Service with clusterIP set to None? Choose two.
- 211. A Pod cannot find the environment variables for a Service that was created after it started. Why?
- 212. What form do the environment variables the kubelet injects for a Service named redis-primary take?
- 213. A Service sets internalTrafficPolicy to Local. What happens to traffic from a Pod on a node with no local endpoints?
- 214. What is the default value of a Service's internalTrafficPolicy?
- 215. How many endpoints does an EndpointSlice hold by default?
- 216. Which objects does kube-proxy treat as the source of truth for routing internal traffic?
- 217. How is an EndpointSlice associated with its Service? Choose two.
- 218. After heavy Pod churn, several EndpointSlices for one Service are only partly full. Why?
- 219. An Ingress object is created but nothing routes traffic. What is most likely missing?
- 220. Why must an Ingress controller be installed deliberately?
- 221. An Ingress is submitted with a path that has no pathType. What happens?
- 222. How do the Exact and Prefix path types differ? Choose two.
- 223. Why can the same Ingress path behave differently on two clusters using ImplementationSpecific?
- 224. An Ingress rule specifies no host. What traffic does it cover?
- 225. What does the ingressClassName field on an Ingress reference?
- 226. Which are stable API kinds in the Gateway API? Choose two.
- 227. How is the Gateway API delivered to a cluster?
- 228. What does a GatewayClass contain?
- 229. Which capability was only reachable in Ingress through controller-specific annotations but is first-class in Gateway API?
- 230. What does it mean that the Ingress API is frozen? Choose two.
- 231. Which ingress controllers does the Kubernetes project itself maintain?
- 232. An administrator requests a clusterIP outside the configured Service range. What does the API server return?
- 233. Within which range must an explicitly chosen clusterIP fall?
- 234. A cluster's Service range is 10.96.0.0/16. Which address do many installers give the DNS Service by convention?
- 235. A load balancer implementation routes straight to Pods and does not need node ports. Which field turns them off?
- 236. allocateLoadBalancerNodePorts is set to false on a Service that already has node ports. Which two statements apply? Choose two.
- 237. Which two statements about loadBalancerClass are correct? Choose two.
- 238. A Service sets loadBalancerClass but no load balancer is ever provisioned. What is the likely cause?
- 239. What is the default ipMode reported for a LoadBalancer Service's ingress address?
- 240. How does trafficDistribution differ from a traffic policy?
- 241. Which proxy modes are available to kube-proxy on a Linux node? Choose two.
- 242. How does kube-proxy in iptables mode choose a backend Pod for a new connection?
- 243. What is the recommended replacement for kube-proxy's deprecated ipvs mode?
- 244. Which kernel version does kube-proxy's nftables mode require?
- 245. Why is it recommended to name kube-proxy's mode explicitly in its configuration?
- 246. Which Service field sends a given client's connections to the same Pod each time?
- 247. What is the default client-IP session stickiness timeout for a Service?
- 248. A Service's cluster IP cannot be pinged, though the Service works. Why?
- 249. A newly created Service has no endpoints and connections to it fail. What should be checked first?
- 250. Which statements about Service type layering are correct? Choose two.
- 379. What does a Pod's Ready condition determine?
- 385. Which check comes first when a Service cannot be reached?
- 387. A Service resolves but returns nothing. Which misconfigurations are likely? Choose two.
- 388. A Service uses a named targetPort but no traffic arrives. What must be true of the Pods?
- 389. A Service has no EndpointSlices at all. What does that point to?
- 390. How is it proved that the application itself is serving, independently of the Service?
- 392. How are kube-proxy's logs found on a node? Choose two.
- 491. Port-forwarding to a Service is used to test load balancing, but every request hits one Pod. Why?
- 640. A StatefulSet's Pods have no resolvable DNS names. Which omission would cause that?
- 661. A container's readiness probe begins failing. Which two things happen? Choose two.
- 701. A Service of type NodePort is created without naming a nodePort value. Which range does the allocated port come from by default?
- 702. A Service is changed from ClusterIP to NodePort. Which two statements are then true? Choose two.
- 703. A Service declares port: 80 and no targetPort. Which container port does traffic reach?
- 704. A Service of type ExternalName maps db to db.example.com. What does a Pod's DNS lookup of db return?
- 705. An application reaching an HTTPS backend through an ExternalName Service gets certificate errors. What explains this?
- 706. An engineer sets externalName to 203.0.113.10 on an ExternalName Service, and nothing resolves. Why?
- 707. How is a headless Service declared?
- 708. Which two statements describe a headless Service? Choose two.
- 709. A headless Service is created without a selector. What constraint applies to its ports?
- 710. A Service is created without a selector so it can front an external database. Nothing can reach it. What is missing?
- 711. A hand-written EndpointSlice named my-service-1 exists alongside a selectorless Service named my-service, but the Service still shows no endpoints. What is most likely wrong?
- 712. At roughly what point does Kubernetes create an additional EndpointSlice for a growing Service?
- 713. A Service backed by 1500 Pods carries the annotation endpoints.kubernetes.io/over-capacity: truncated. What does that indicate?
- 714. Which two shortcomings of the Endpoints API led to EndpointSlice replacing it? Choose two.
- 715. A Service sets trafficDistribution to PreferSameZone. What does this guarantee?
- 716. A manifest sets trafficDistribution to PreferClose. What is the current guidance?
- 717. An application needs a client's requests to keep landing on the same Pod. What does a Service offer?
- 718. A Service declares two ports and the API server rejects it. Which requirement was most likely missed?
- 719. Which of these is a valid name for a Service port?
- 720. A LoadBalancer Service has been created but kubectl get svc shows its external address as pending. Where will the address appear once provisioned?
- 721. How does Kubernetes typically implement a LoadBalancer Service?
- 722. A Service sets internalTrafficPolicy to Local. A Pod on a node with no ready endpoint for that Service tries to connect. What happens?
- 723. Why is externalTrafficPolicy: Local often chosen for a LoadBalancer Service?
- 724. Under externalTrafficPolicy: Cluster, which endpoint do load balancer health checks target?
- 725. Why does kube-proxy return 503 from /healthz while its node is being deleted?
- 726. A vendor configures kube-proxy's /healthz as a liveness probe, and kube-proxy restarts continuously while a node is being deleted. Which path should have been used?
- 727. In iptables proxy mode, how is a backend chosen for a new connection to a Service?
- 728. An operator is choosing a kube-proxy mode for a new Linux cluster and is considering ipvs. What is the current guidance?
- 729. Which two capabilities does IPVS proxy mode offer that iptables mode does not? Choose two.
- 730. A very large cluster in iptables mode sees kube-proxy take a long time to converge after a change. What is the underlying cause?
- 731. A team wants to expose a PostgreSQL database to clients outside the cluster. Why is an Ingress the wrong tool?
- 732. An Ingress object has been applied successfully but no traffic is routed and its address stays empty. What should be checked first?
- 733. An Ingress manifest defines a path with no pathType. What happens?
- 734. An Ingress has a Prefix path of /foo/bar. Which two request paths match? Choose two.
- 735. An Ingress has an Exact path of /foo. Which request path matches it?
- 736. An Ingress declares /foo as a Prefix path and /foo as an Exact path, pointing at different Services. Where does a request for /foo go?
- 737. An Ingress rule uses the host *.foo.com. Which Host header matches?
- 738. An Ingress is written with no rules at all. What must it contain to be valid?
- 739. Two IngressClasses in a cluster are both annotated as the default. What is the consequence?
- 740. Which two statements about Ingress TLS are correct? Choose two.
- 741. Which keys must a Secret contain to be used as an Ingress TLS certificate?
- 742. An Ingress terminates TLS for shop.example.com but its rules only define a default backend with no host. Why does TLS not work?
- 743. A dual-stack Service serves both IPv4 and IPv6. How many EndpointSlices does it have at a minimum?
- 744. An endpoint in an EndpointSlice reports serving: true and terminating: true. What is its ready condition?
- 745. Every endpoint of a Service is terminating at once. What do Service proxies do?
- 746. In Gateway API, what is the relationship between a Gateway and a GatewayClass?
- 747. A team needs weighted traffic splitting between two backend versions. What does Gateway API offer that Ingress does not?
- 748. A Service manifest requests a specific clusterIP that another Service already holds. What does the API server do?
- 749. A Pod reads a Service's address from the injected environment variables, but the variables are missing. What is the most likely reason?
- 750. A NodePort Service has three backing Pods on three of a cluster's ten nodes. Which nodes answer on the allocated node port?
- 768. A Pod resolves the DNS name of a headless Service. What does it get back?
- 771. For which Service ports does cluster DNS create SRV records?
- 784. A Service sets ipFamilyPolicy to RequireDualStack and is applied to a single-stack cluster. What happens?
- 785. Which field determines a dual-stack Service's primary IP family?
- 859. Which command lists the EndpointSlices belonging to a Service named web?
- 860. A Service has no endpoints. What is the most direct way to confirm the cause?
- 861. A Service has endpoints and its selector is correct, yet connections are refused. Which mismatch should be checked next?
- 874. A Service manifest written in JSON has "targetPort": "9376". What is wrong?
- 875. A Service selects app=hostnames but its EndpointSlice shows no endpoints, while the Pods are Running. What should be inspected?
- 876. You want to separate a broken Service from a broken application. Which test does that?
- 877. A Service works most of the time but fails intermittently, and its backing Pods show a high RESTARTS count. How are the two connected?
- 878. A Service resolves, has correct endpoints, and each Pod answers when addressed directly, yet the Service IP does not work. What is the remaining suspect?
- 879. kube-proxy's logs do not show which endpoints it programmed for a Service. What does the guide suggest?
- 984. A Pod is terminating gracefully. What happens to its entry in the Service's EndpointSlice?