20+ practice questions focused on Services and Networking — one of the most tested topics on the Certified Kubernetes Administrator CKA exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Services and Networking PracticeAn administrator runs 'kubectl run nginx --image=nginx --port=80' and then 'kubectl expose pod nginx --port=80 --type=NodePort'. Later, they run 'kubectl get svc nginx' and see that the NodePort is set to 0. What is the most likely reason?
Explanation: By default, Kubernetes restricts NodePort allocations to the range 30000-32767. If a user specifies a nodePort outside of this range (such as 8080) in the Service manifest, the API server will reject the creation with a validation error. This range can be customized using the `--service-node-port-range` flag on the kube-apiserver.
A cluster has a NetworkPolicy that denies all ingress traffic by default. An administrator wants to allow TCP traffic on port 8080 from pods with label 'app: web' in the same namespace. Which NetworkPolicy egress rule is needed?
Explanation: To allow incoming traffic to a pod that has a default-deny ingress policy, an ingress rule must be defined on that pod's NetworkPolicy. The rule needs to specify a podSelector matching the source pods ('app: web') and the destination port (8080).
Which TWO of the following are valid ways to expose a Deployment named 'web' as a service?
Explanation: Option C is correct because `kubectl expose deployment web --port=80` is the canonical imperative command that creates a Service whose selector is automatically derived from the Deployment's pod template labels, targeting the pods managed by the 'web' Deployment. Option D is correct because applying a Service manifest with `selector: app: web` creates a Service that selects the pods labeled `app: web`, which is the standard declarative way to expose a Deployment's pods (assuming the Deployment's pod template carries that label). Option A is not a Service at all; `kubectl port-forward` only tunnels a local port to a pod/Deployment for debugging and does not create a persistent Service object. Option B uses `kubectl run --expose`, which creates a new pod (and a Service for it), not a Service exposing the existing 'web' Deployment. Option E creates a ClusterIP Service named 'web' but with no selector tied to the Deployment's pods, so it would not route traffic to the Deployment's replicas.
Which THREE of the following are requirements for an Ingress resource to work?
Explanation: Option B is correct because an Ingress resource is only a declarative specification; without an Ingress controller (e.g., ingress-nginx, Traefik, HAProxy) running in the cluster, no component watches the Ingress object and programs the underlying load balancer or proxy, so no routing occurs. Option D is correct because the Ingress routes traffic to backend Services, and those Services must exist with ready endpoints (pods passing readiness probes) for requests to be forwarded; otherwise the controller returns 503 errors. Option E is correct because an Ingress spec requires rules containing at least one path (e.g., path: / with pathType: Prefix) mapping to a backend service and port; a rule with no path rules provides nothing to route. Option A is not required because the host field is optional — a rule without a host matches all inbound HTTP traffic. Option C is not required because TLS is optional; an Ingress can serve plain HTTP without a tls section.
Which TWO of the following statements about NetworkPolicy are true?
Explanation: Option A is correct because a single NetworkPolicy object can define both an ingress section (rules for incoming traffic to the selected pods) and an egress section (rules for outgoing traffic from the selected pods), allowing bidirectional control. Option C is correct because NetworkPolicies are additive: if multiple policies select the same pod, the union of all their rules applies, so a pod can be governed by several NetworkPolicies simultaneously. Option B is not correct because NetworkPolicy selectors work on pod, namespace, and IPBlock labels/selectors for peers, but the statement as phrased about filtering by source IP addresses alone is not the defining behavior being tested. Option D is not correct because NetworkPolicy is a namespaced resource, not cluster-scoped. Option E is not correct because by default pods are non-isolated and all ingress and egress traffic is allowed; isolation only occurs once a policy selects the pod.
+15 more Services and Networking questions available
Practice all Services and Networking questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Services and Networking. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Services and Networking questions on the CKA frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Services and Networking is tested as part of the Certified Kubernetes Administrator CKA blueprint. Practicing with targeted Services and Networking questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CKA practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Services and Networking is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Services and Networking practice session with instant scoring and detailed explanations.
Start Services and Networking Practice →