Courseiva
Services and Networking →hardMultiple Choice

CKA Services and Networking Practice Question

A Kubernetes cluster uses kube-proxy in iptables mode. A Service named 'web-svc' of type ClusterIP has three endpoints: pod A (10.244.1.5:8080), pod B (10.244.2.6:8080), and pod C (10.244.3.7:8080). A client pod repeatedly sends requests to the Service's ClusterIP. The administrator observes that all requests from a single client pod are being routed to pod A, even though pod B and pod C are healthy. Which of the following is the most likely explanation?

⚠ Common exam trap

The trap here is assuming that iptables mode always distributes evenly across endpoints, overlooking the possibility of session affinity being enabled.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Service has sessionAffinity set to ClientIP, which causes kube-proxy to route all requests from the same client IP to the same endpoint for the duration of the session affinity timeout.

The most likely explanation is that the Service has sessionAffinity set to ClientIP. This setting makes kube-proxy route all requests from a particular client IP to the same backend pod for a configurable duration. Since the client pod's IP is constant, all its requests go to pod A. This is a deliberate feature for session persistence, not a load-balancing bug.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kube-proxy in iptables mode uses random selection for each packet, so the client should see distribution across all endpoints; the observed behavior indicates a bug in kube-proxy.

    Why it's wrong here

    kube-proxy in iptables mode does not use random selection per packet; it uses a probabilistic algorithm that can lead to uneven distribution, but not all traffic to one pod. The observed behavior is more likely due to session affinity being enabled, which is a deliberate feature, not a bug. This option mischaracterizes the load-balancing behavior.

  • ✗

    The client pod is using a persistent HTTP connection, and the Service is using IPVS mode with a least-connections algorithm, which sticks to one backend.

    Why it's wrong here

    The scenario specifies kube-proxy in iptables mode, not IPVS. In iptables mode, there is no least-connections algorithm; that is an IPVS feature. Persistent connections alone do not cause all traffic to go to one pod in iptables mode; session affinity does. This option mixes up modes and features.

  • ✗

    The endpoints for pod B and pod C are not ready, so kube-proxy only routes to pod A; the administrator should check readiness probes.

    Why it's wrong here

    The scenario states that pod B and pod C are healthy, implying they are ready and included in the endpoints. If they were not ready, they would be excluded, but that is not the case here. The uniform routing to pod A suggests a different mechanism, such as session affinity, rather than a readiness issue.

  • ✓

    The Service has sessionAffinity set to ClientIP, which causes kube-proxy to route all requests from the same client IP to the same endpoint for the duration of the session affinity timeout.

    Why this is correct

    When sessionAffinity is set to ClientIP, kube-proxy implements client IP-based session affinity, directing all requests from a given client IP to the same backend pod for the configured timeout (default 3 hours). This exactly matches the scenario where a single client pod's requests all go to pod A. It is a common configuration for stateful applications.

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.