CKA Services and Networking Practice Question
Which kubectl command will expose a deployment named 'web-app' as a NodePort service on port 80?
⚠ Common exam trap
Many exam-takers confuse `kubectl expose` with `kubectl create service` or misuse the `--expose` flag on `kubectl create deployment`, not realizing that `kubectl expose` is the correct command to create a service from an existing resource and that the `--type=NodePort` flag is required for NodePort exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl expose deployment web-app --type=NodePort --port=80
The `kubectl expose deployment web-app --type=NodePort --port=80` command creates a Service from an existing Deployment named 'web-app', setting the service type to NodePort and mapping port 80 on the node to the target port on the pods. This is the standard way to expose a Deployment as a NodePort service in Kubernetes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl expose pod web-app --type=NodePort --port=80
Why it's wrong here
This command attempts to expose a single Pod resource instead of the requested Deployment. In addition to targeting the wrong resource type, exposing individual Pods directly bypasses the controller-managed replica set, which is not a standard or resilient practice in Kubernetes.
- ✗
kubectl create deployment web-app --expose --port=80
Why it's wrong here
While the `kubectl create deployment` command can generate a deployment, appending the `--expose` flag is invalid syntax for this generator. Even if it were supported, it would default to creating a ClusterIP service rather than the NodePort service required to expose the application to external traffic.
- ✗
kubectl create service nodeport web-app --port=80
Why it's wrong here
The `kubectl create service nodeport` command creates a generic, empty service without automatically mapping its selectors to the labels of the `web-app` deployment. To properly expose an existing workload, you must use `kubectl expose`, which automatically inherits the correct label selectors from the target deployment.
- ✓
kubectl expose deployment web-app --type=NodePort --port=80
Why this is correct
This command correctly targets the `deployment` resource named `web-app` and dynamically generates a NodePort service. It automatically extracts the deployment's pod template labels to populate the service's selector, ensuring seamless routing of external traffic on the specified port.
Go deeper
Related to this question
Learn chapter
Installing Kubernetes with kubeadm
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
ClusterIP NodePort LoadBalancer
ClusterIP, NodePort, and LoadBalancer are three types of Kubernetes Services that control how traffic reaches your application pods inside the cluster or from outside.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.