You must create, inspect, and troubleshoot Services, Ingress, DNS, and NetworkPolicy. The most important thing is to verify connectivity with kubectl exec and nslookup, and to remember that NetworkPolicy is additive and default-deny once a pod is selected.
Start practicing
Services & Networking — choose a session length
Free · No account required
Domain overview
The Services & Networking domain covers Kubernetes networking primitives: Service types (ClusterIP, NodePort, LoadBalancer, ExternalName), headless Services, Ingress, NetworkPolicy, and cluster DNS. You are tested through hands-on tasks: creating and troubleshooting Services, configuring DNS resolution, and applying NetworkPolicy rules that allow or deny traffic between pods and namespaces.
Exam objectives
Creating and exposing applications with ClusterIP, NodePort, LoadBalancer, and ExternalName Services
Using headless Services for direct pod DNS records and StatefulSet stable network identities
Configuring pod DNS policies and resolving Service names across namespaces with cluster DNS
Writing NetworkPolicy ingress and egress rules to control pod traffic by labels and ports
Assuming a ClusterIP Service is reachable from outside the cluster; only NodePort or LoadBalancer expose ports externally.
Forgetting that a NetworkPolicy selecting pods denies all traffic not explicitly allowed by an ingress or egress rule.
Using the wrong namespace-qualified DNS name for cross-namespace Service access, such as missing the namespace or cluster domain suffix.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A cluster has multiple namespaces: 'frontend', 'backend', and 'monitoring'. A pod in the 'frontend' namespace needs to reach a Service named 'db-service' in the 'backend' namespace. The 'db-service' Service is of type ClusterIP. Which DNS name should the pod use?
2A pod is running with the default DNS policy. The cluster DNS service is at 10.96.0.10. The node's /etc/resolv.conf has nameserver 8.8.8.8. When the pod tries to resolve an external hostname like 'example.com', which DNS server will it query first?
3An administrator notices that traffic to a Service is not being forwarded to any pod. The Service has selector 'app: web' and there are pods with that label. However, 'kubectl get endpoints' shows no endpoints. What is the most likely cause?
4A Kubernetes cluster uses Calico as the CNI plugin. Two pods on different nodes cannot communicate, but pods on the same node can. Network policies are not enforced. What is the most likely cause?
5A company wants to expose a web application running as a Deployment with 3 replicas to external users. They need a stable IP address that does not change and the ability to terminate TLS. Which resource should they use?
6Which TWO of the following are valid reasons to use a Headless Service?
7You are tasked with troubleshooting a web application that is deployed in a Kubernetes cluster. The application consists of a Deployment named 'web-app' with 3 replicas, each running a container that listens on port 3000. A Service named 'web-service' of type ClusterIP with selector 'app: web' and port 80 targeting port 3000 has been created. Additionally, an Ingress resource named 'web-ingress' is configured with a host rule for 'example.com' and backend service 'web-service' on port 80. Users report that accessing http://example.com results in a 503 Service Unavailable error. You verify that all pods are running, but kubectl get pods shows the READY column as 0/1 for each pod. The Ingress controller logs show 'upstream connect error or disconnect/reset before headers'. You check the endpoints: 'kubectl get endpoints web-service' shows no endpoints. The pods have the label 'app: web'. What should you do to resolve the issue?
8A company deploys a web application with multiple replicas in a Kubernetes cluster. Users report intermittent connectivity issues. The application pods are exposed via a ClusterIP Service. To ensure stable connectivity, which action should be taken?
9Given the following YAML manifests in the same namespace: ```yaml apiVersion: v1 kind: Pod metadata: name: my-pod labels: app: my-app spec: containers: - name: app image: nginx ports: - containerPort: 8080 --- apiVersion: v1 kind: Service metadata: name: my-service spec: selector: app: my-app ports: - port: 80 targetPort: 8080 ``` A pod in the same namespace tries to reach my-service on port 80. What is the most likely outcome?
10A Kubernetes cluster has a Service named 'web-svc' of type ClusterIP in the 'production' namespace. The Service selects pods with label 'app=web'. A NetworkPolicy in the same namespace is applied with the following spec: ```yaml apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-web spec: podSelector: matchLabels: app: web policyTypes: - Ingress ingress: - from: - podSelector: matchLabels: role: frontend ``` A pod with label 'role=frontend' in the 'staging' namespace attempts to connect to 'web-svc.production.svc.cluster.local' on port 80. What is the result?
11A Kubernetes cluster uses kube-proxy in IPVS mode. A Service named 'api-svc' of type ClusterIP has three endpoints: 10.244.1.5:8080, 10.244.2.6:8080, and 10.244.3.7:8080. A client pod repeatedly connects to 'api-svc' and observes that all connections are routed to the same endpoint, 10.244.1.5:8080. The client pod and the endpoints are on different nodes. What is the most likely cause?
You must create, inspect, and troubleshoot Services, Ingress, DNS, and NetworkPolicy. The most important thing is to verify connectivity with kubectl exec and nslookup, and to remember that NetworkPolicy is additive and default-deny once a pod is selected.
The Courseiva CKA question bank contains 11 questions in the Services & Networking domain, covering the 10% of the exam attributed to this domain in the official CNCF blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Services & Networking domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included