CKA · domain
Services & Networking
The Services & Networking domain covers Kubernetes networking primitives: Service types (ClusterIP, NodePort, LoadBalancer, ExternalName), headless Services, Ingress, NetworkPolicy, and cluster DNS. You are tested through hands-on tasks: creating and troubleshooting Services, configuring DNS resolution, and applying NetworkPolicy rules that allow or deny traffic between pods and namespaces.
Focused practice
Practice Services & Networking questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Services & Networking
You must create, inspect, and troubleshoot Services, Ingress, DNS, and NetworkPolicy. The most important thing is to verify connectivity with kubectl exec and nslookup, and to remember that NetworkPolicy is additive and default-deny once a pod is selected.
Creating and exposing applications with ClusterIP, NodePort, LoadBalancer, and ExternalName Services
Using headless Services for direct pod DNS records and StatefulSet stable network identities
Configuring pod DNS policies and resolving Service names across namespaces with cluster DNS
Writing NetworkPolicy ingress and egress rules to control pod traffic by labels and ports
Watch out for
Common Services & Networking exam traps
- ▸Assuming a ClusterIP Service is reachable from outside the cluster; only NodePort or LoadBalancer expose ports externally.
- ▸Forgetting that a NetworkPolicy selecting pods denies all traffic not explicitly allowed by an ingress or egress rule.
- ▸Using the wrong namespace-qualified DNS name for cross-namespace Service access, such as missing the namespace or cluster domain suffix.
Question index
All Services & Networking questions (11)
Click any question to see the full explanation, or start a practice session above.
A pod is running with the default DNS policy. The cluster DNS service is at 10.96.0.10. The node's /etc/resolv.conf has nameserver 8.8.8.8. When the pod tries to resolve an external hostname like 'example.com', which DNS server will it query first?
Easy2A Kubernetes cluster has a Service named 'web-svc' of type ClusterIP in the 'production' namespace. The Service selects pods with label 'app=web'. A NetworkPolicy in the same namespace is applied with the following spec: ```yaml apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-web spec: podSelector: matchLabels: app: web policyTypes: - Ingress ingress: - from: - podSelector: matchLabels: role: frontend ``` A pod with label 'role=frontend' in the 'staging' namespace attempts to connect to 'web-svc.production.svc.cluster.local' on port 80. What is the result?
Medium3A Kubernetes cluster uses Calico as the CNI plugin. Two pods on different nodes cannot communicate, but pods on the same node can. Network policies are not enforced. What is the most likely cause?
Hard4An administrator notices that traffic to a Service is not being forwarded to any pod. The Service has selector 'app: web' and there are pods with that label. However, 'kubectl get endpoints' shows no endpoints. What is the most likely cause?
Medium5You are tasked with troubleshooting a web application that is deployed in a Kubernetes cluster. The application consists of a Deployment named 'web-app' with 3 replicas, each running a container that listens on port 3000. A Service named 'web-service' of type ClusterIP with selector 'app: web' and port 80 targeting port 3000 has been created. Additionally, an Ingress resource named 'web-ingress' is configured with a host rule for 'example.com' and backend service 'web-service' on port 80. Users report that accessing http://example.com results in a 503 Service Unavailable error. You verify that all pods are running, but kubectl get pods shows the READY column as 0/1 for each pod. The Ingress controller logs show 'upstream connect error or disconnect/reset before headers'. You check the endpoints: 'kubectl get endpoints web-service' shows no endpoints. The pods have the label 'app: web'. What should you do to resolve the issue?
Hard6A company deploys a web application with multiple replicas in a Kubernetes cluster. Users report intermittent connectivity issues. The application pods are exposed via a ClusterIP Service. To ensure stable connectivity, which action should be taken?
Medium7A cluster has multiple namespaces: 'frontend', 'backend', and 'monitoring'. A pod in the 'frontend' namespace needs to reach a Service named 'db-service' in the 'backend' namespace. The 'db-service' Service is of type ClusterIP. Which DNS name should the pod use?
Hard8Which TWO of the following are valid reasons to use a Headless Service?
Easy9A Kubernetes cluster uses kube-proxy in IPVS mode. A Service named 'api-svc' of type ClusterIP has three endpoints: 10.244.1.5:8080, 10.244.2.6:8080, and 10.244.3.7:8080. A client pod repeatedly connects to 'api-svc' and observes that all connections are routed to the same endpoint, 10.244.1.5:8080. The client pod and the endpoints are on different nodes. What is the most likely cause?
Hard10A company wants to expose a web application running as a Deployment with 3 replicas to external users. They need a stable IP address that does not change and the ability to terminate TLS. Which resource should they use?
Medium11Given the following YAML manifests in the same namespace: ```yaml apiVersion: v1 kind: Pod metadata: name: my-pod labels: app: my-app spec: containers: - name: app image: nginx ports: - containerPort: 8080 --- apiVersion: v1 kind: Service metadata: name: my-service spec: selector: app: my-app ports: - port: 80 targetPort: 8080 ``` A pod in the same namespace tries to reach my-service on port 80. What is the most likely outcome?
EasyOther domains
All CKA exam domains
Frequently asked questions
- What does the Services & Networking domain cover on the CKA exam?
- You must create, inspect, and troubleshoot Services, Ingress, DNS, and NetworkPolicy. The most important thing is to verify connectivity with kubectl exec and nslookup, and to remember that NetworkPolicy is additive and default-deny once a pod is selected.
- How many questions are in this domain?
- This page lists all 11 Services & Networking questions in the CKA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Services & Networking questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.