CKA Services and Networking Practice Question
A developer runs 'kubectl port-forward service/my-service 8080:80'. What does this command do?
⚠ Common exam trap
It's easy for candidates to confuse `kubectl port-forward` with `kubectl expose` or `kubectl proxy`, mistakenly thinking it creates a permanent Service or NodePort, when in fact it only creates a temporary, client-side tunnel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It forwards incoming traffic on local port 8080 to port 80 on the service's ClusterIP.
`kubectl port-forward` creates a tunnel from a local port on the client machine to a specified port on a Kubernetes resource, in this case a Service. It forwards traffic received on localhost:8080 to the Service's ClusterIP on port 80, allowing the developer to access the service without exposing it externally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It creates a proxy that routes traffic from the service's ClusterIP to the local machine on port 8080.
Why it's wrong here
This option incorrectly reverses the direction of the traffic flow. The port-forward command initiates a local listener on your workstation at port 8080 and tunnels traffic into the Kubernetes cluster, rather than routing traffic originating from the ClusterIP back to your local machine.
- ✓
It forwards incoming traffic on local port 8080 to port 80 on the service's ClusterIP.
Why this is correct
This is the correct behavior of the command. It binds to port 8080 on the local loopback interface and securely tunnels any connection made to localhost:8080 through the API server to port 80 of the specified Service, which then routes it to the backing Pods.
- ✗
It exposes the service as a NodePort on port 8080.
Why it's wrong here
Port forwarding is a temporary, client-side diagnostic tool that does not alter the Kubernetes resource definitions. It does not modify the Service's specification to change its type to NodePort, nor does it open any ports on the cluster's physical worker nodes.
- ✗
It creates a new service of type LoadBalancer on port 8080.
Why it's wrong here
This command does not provision any new Kubernetes resources or interact with cloud provider APIs to spin up an external load balancer. It simply establishes a temporary network tunnel between your local machine and an existing Service resource for debugging purposes.
Go deeper
Related to this question
Learn chapter
Kubernetes Architecture Overview
Key term
ClusterIP NodePort LoadBalancer
ClusterIP, NodePort, and LoadBalancer are three types of Kubernetes Services that control how traffic reaches your application pods inside the cluster or from outside.
Key term
kubectl Command Reference
kubectl is the command-line tool used to interact with and manage Kubernetes clusters by sending commands to the Kubernetes API.
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.