20+ practice questions focused on Services and Networking — one of the most tested topics on the Certified Kubernetes Application Developer CKAD exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Services and Networking PracticeAn application requires Pods to communicate using hostNetwork: true. Which Kubernetes resource is still necessary for stable DNS names?
Explanation: When Pods use hostNetwork: true, they share the node's network namespace, so their endpoint IP is the node IP. A regular ClusterIP Service still creates stable DNS records (via CoreDNS) that resolve to the Service's virtual IP. kube-proxy will still set up iptables rules to forward traffic from the ClusterIP to the endpoint (node IP), so ClusterIP connectivity is not lost. A Service object is still necessary for stable DNS names. Note: A headless Service also provides a stable DNS name, but it resolves to the individual pod/node IPs instead of a single virtual IP.
You have deployed a microservices application in a Kubernetes cluster. One of the services, 'payment-service', needs to be accessed by other services within the cluster via a stable DNS name. You create a Service of type ClusterIP named 'payment' with selector app=payment. However, when you try to curl http://payment from another Pod, the connection times out. You verify that the Pods backing 'payment-service' are running and ready, and the Endpoints object lists the correct Pod IPs. You also confirm that the Pods are listening on port 8080, and the Service defines targetPort: 8080. The cluster uses a standard CNI plugin (Calico) and DNS is provided by CoreDNS. What is the most likely cause of the timeout?
Explanation: The most likely cause is that the Pods are listening only on 127.0.0.1 (localhost), so they only accept connections from within the same Pod. When the Service sends traffic to the Pod via its cluster IP, the connection arrives on the Pod's network interface (e.g., eth0), not on loopback. Since the application is not bound to 0.0.0.0, the kernel rejects the SYN with a TCP RST, and the client typically sees 'connection refused'. (A timeout could occur if a network policy is silently dropping packets, but the localhost bind is the most common and direct issue.)
A DevOps engineer notices that traffic to a Service named 'api' is not being forwarded to newly created pods. The Service selects pods with label 'app: api'. The pods are running and have the correct label. However, the Service's endpoints list does not include the new pods. What is the most likely cause?
Explanation: The Service's `targetPort` must match the `containerPort` defined in the pod's container spec. If they differ, the Service will not route traffic to the pod, and the pod will not appear in the Endpoints object, even if the label selector matches. Kubernetes validates the endpoint population by checking that the pod's readiness probe passes and that the target port is reachable on the pod's IP.
During a security audit, it is discovered that a pod running a database is accessible from any other pod in the cluster. The database should only be accessible by pods with label 'role: backend'. Which resource should be applied to enforce this restriction?
Explanation: A NetworkPolicy with an ingress rule that selects pods with label 'role: backend' explicitly restricts inbound traffic to the database pod to only those pods that match that label. NetworkPolicies are Kubernetes-native resources that enforce firewall rules at the IP address or port level (OSI layer 3 or 4) using the pod's labels as selectors, and they are the standard mechanism for controlling pod-to-pod traffic within a cluster.
A developer deploys a web application as a Deployment named 'web-app' with 3 replicas. The application listens on port 8080 and should be accessible from within the cluster via the service name 'web-svc' on port 80. Which Service YAML correctly exposes the application?
Explanation: Option A is correct because it defines a ClusterIP Service that maps port 80 to targetPort 8080 and uses the selector `app: web-app` to match the Pods. Option D is incorrect because it uses the selector `name: web-app`, which does not match the Pods labeled with `app: web-app`. Option B is incorrect because it adds `type: NodePort`, which is unnecessary for internal cluster access and may expose the service externally. Option C incorrectly swaps `port` and `targetPort`, sending traffic to the wrong container port.
+15 more Services and Networking questions available
Practice all Services and Networking questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Services and Networking. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Services and Networking questions on the CKAD frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Services and Networking is tested as part of the Certified Kubernetes Application Developer CKAD blueprint. Practicing with targeted Services and Networking questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CKAD practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Services and Networking is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Services and Networking practice session with instant scoring and detailed explanations.
Start Services and Networking Practice →