200-901 Application Deployment and Security Practice Question
A developer is deploying a containerized application to a Kubernetes cluster. The application must be accessible from outside the cluster on a stable IP address that does not change if the underlying pods are rescheduled. Which Kubernetes Service type should be used?
⚠ Common exam trap
The trap here is assuming that NodePort provides a stable external IP, when in fact the IP is tied to individual nodes and can change.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
LoadBalancer
A LoadBalancer Service integrates with the underlying cloud provider to provision an external load balancer with a stable IP address. This IP persists independently of pod or node lifecycle events, ensuring consistent external access. ClusterIP, NodePort, and ExternalName each fail to provide a stable external IP for the application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ExternalName
Why it's wrong here
ExternalName maps a Service to a DNS name, essentially creating a CNAME record. It does not allocate an IP address or provide any proxying; it simply returns the configured external name. This is used for accessing external services from within the cluster, not for exposing an internal application to external clients on a stable IP.
- ✓
LoadBalancer
Why this is correct
LoadBalancer provisions an external load balancer (typically via the cloud provider) that assigns a stable, externally reachable IP address. This IP remains consistent even if pods are rescheduled or nodes are replaced. It automatically routes traffic to the appropriate NodePort and ClusterIP, fulfilling the requirement for stable external access to the application.
- ✗
NodePort
Why it's wrong here
NodePort exposes the Service on each node's IP at a static port, allowing external access. However, the accessible IP is the node's IP, which can change if nodes are replaced, and it does not provide a single stable external IP. While it offers external access, it does not meet the stable IP requirement as well as a LoadBalancer Service does.
- ✗
ClusterIP
Why it's wrong here
ClusterIP exposes the Service on a cluster-internal IP, making it reachable only from within the cluster. It is the default type and is used for internal communication between components. Because it provides no external IP and no external load balancer, it cannot satisfy the requirement of external accessibility on a stable IP that persists across pod rescheduling.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.