200-901 Application Deployment and Security Practice Question
Which THREE options are valid methods to expose a Kubernetes service to external traffic?
⚠ Common exam trap
The trap is including ExternalName or ClusterIP as external exposure methods — candidates confuse DNS aliasing and internal-only networking with actual external accessibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NodePort
NodePort (B) is correct because it allocates a static port in the 30000-32767 range on every node's IP, allowing external clients to reach the service via <NodeIP>:<NodePort>. Ingress (D) is correct because it provides HTTP/HTTPS routing from outside the cluster to internal services through an ingress controller acting as a reverse proxy. LoadBalancer (E) is correct because it provisions an external load balancer (e.g., via a cloud provider) with a public IP that forwards traffic to the service's NodePort. ExternalName (A) is not a valid exposure method for external traffic; it merely creates a CNAME DNS alias to an external hostname without proxying traffic. ClusterIP (C) is incorrect because it only exposes the service on an internal cluster IP reachable solely from within the cluster.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ExternalName
Why it's wrong here
ExternalName maps a Service to a DNS CNAME, returning only that alias to in-cluster lookups; it creates no proxy, load balancer or external IP, so outside clients cannot reach the pods. It suits abstracting an external dependency, such as a managed database, behind an internal name.
- ✓
NodePort
Why this is correct
NodePort opens a static port on every cluster node, forwarding external traffic to the service's ClusterIP. This satisfies the requirement for exposing a service externally without a cloud load balancer, since kube-proxy listens on that port range (30000–32767) across all nodes.
- ✗
ClusterIP
Why it's wrong here
ClusterIP assigns only an internal virtual IP reachable within the cluster, so it never exposes a service externally. It is tempting because it is the default Service type and does provide stable in-cluster access, which is exactly the scenario where it is the right choice.
- ✓
Ingress
Why this is correct
Ingress exposes HTTP and HTTPS routes from outside the cluster to services within it, satisfying the requirement for external traffic. Rules defined on the Ingress resource map hostnames and paths to backend services, with an ingress controller implementing the routing. This provides layer 7 exposure rather than the layer 4 approach of NodePort or LoadBalancer.
- ✓
LoadBalancer
Why this is correct
A LoadBalancer Service requests an external load balancer from the cloud provider, which provisions a public IP and routes external traffic to the Service's pods. This satisfies the requirement to expose the service externally, unlike ClusterIP, which is reachable only inside the cluster.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.