Courseiva
Services and Networking →mediumMultiple Choice

CKA Services and Networking Practice Question

An Ingress resource uses 'networking.k8s.io/v1' API. Which field specifies the hostname and path rules for routing traffic?

⚠ Common exam trap

A common trap in the CKA exam is confusing 'spec.rules' with 'spec.backend'. While 'spec.backend' defines a default backend, 'spec.rules' is the correct field for hostname and path-based routing rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

spec.rules

In the 'networking.k8s.io/v1' Ingress API, the 'spec.rules' field is where you define an array of routing rules, each containing a 'host' field for the hostname and an 'http' subfield with 'paths' that specify path-based routing to backend services. This is the primary mechanism for directing traffic based on hostname and path.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    spec.ingress

    Why it's wrong here

    The Ingress API does not define a spec.ingress field. In networking.k8s.io/v1, the IngressSpec contains only rules, tls, defaultBackend, and ingressClassName. Any attempt to set spec.ingress would be rejected by the API server because the field is not recognized, so it cannot hold routing information.

  • ✗

    spec.tls

    Why it's wrong here

    The spec.tls field configures Transport Layer Security, listing hosts that need HTTPS and referencing a Kubernetes Secret that contains the certificate and private key. It does not define how requests are routed to services; instead, routing is entirely handled by the rules field with host, path, and backend maps. TLS only governs encryption, not traffic distribution.

  • ✓

    spec.rules

    Why this is correct

    The spec.rules field is the heart of ingress routing, containing an ordered list of HTTP rules. Each rule can specify an optional host and a set of HTTP paths, each with a pathType (Prefix or Exact) and a backend that points to a Service and port. When incoming traffic matches the host and path criteria, it is forwarded to the specified backend. This is exactly what defines routing rules in an Ingress.

  • ✗

    spec.backend

    Why it's wrong here

    spec.backend is a legacy alias not present in networking.k8s.io/v1; the correct field is defaultBackend, which specifies a fallback backend for requests that do not match any rule in spec.rules. It functions as a catch-all service, not as a routing rule itself. Since it only handles unmatched traffic, it cannot replace or define host/path-based routing.

About these practice questions

This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.