Courseiva
Services and Networking →mediumMultiple Select

CKA Services and Networking Practice Question

Which of the following can be used to expose a set of pods externally to the internet in a Kubernetes cluster? (Select THREE.)

⚠ Common exam trap

A common mistake is thinking that a Headless service can be used for external exposure because it still has a DNS name, but it lacks any IP or port mapping for external traffic. Headless services are intended for internal service discovery, not external exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ingress resource

An Ingress resource (A) exposes HTTP/HTTPS routes from outside the cluster to Services inside the cluster, acting as a layer-7 entry point with rules and TLS termination, so it can publish a set of pods to the internet. A Service of type NodePort (B) exposes the Service on each node's IP at a static port (default range 30000-32767), making the pods reachable externally via any node IP and that port. A Service of type LoadBalancer (C) provisions an external load balancer (e.g., via a cloud provider) that routes internet traffic to the Service's endpoints, directly exposing the pods externally. A headless Service (D) sets clusterIP: None and returns pod IPs directly via DNS for direct pod addressing, but it does not provide an external entry point. A Service of type ClusterIP (E) only assigns a virtual IP reachable within the cluster, so it is not externally accessible without additional components like Ingress or NodePort.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Ingress resource

    Why this is correct

    Ingress is not a Service type but a separate Kubernetes API object that exposes HTTP and HTTPS routes from outside the cluster to Services. It operates at Layer 7, allowing hostname- and path-based routing, TLS termination, and virtual hosting, and it requires an Ingress controller (e.g., NGINX, Traefik) to interpret and implement the rules.

  • ✓

    Service of type NodePort

    Why this is correct

    A NodePort Service is built on top of ClusterIP and opens a static port in the 30000-32767 range on every node, so the Service is reachable externally via any node's IP address combined with that port. This type directly exposes the Service without provisioning an external load balancer, making it useful for quick testing or on bare metal, but it leaves management of node IPs and ports to the user.

  • ✓

    Service of type LoadBalancer

    Why this is correct

    A LoadBalancer Service is an extension of NodePort that, in cloud environments, provisions an external load balancer (like AWS ELB or GCP LB) with a stable public IP address. It automatically routes external traffic to the underlying NodePorts, abstracting away node-level details, and is the standard way to expose Services in cloud-native apps when you need a single externally reachable IP.

  • ✗

    Service of type Headless

    Why it's wrong here

    A Headless Service (clusterIP: None) does not expose a Service externally; instead, it returns the IP addresses of the backing pods directly via DNS, enabling client-to-pod discovery. It is used for stateful workloads like databases, or for service discovery when you need to resolve individual pod IPs, but it never provides external connectivity or load balancing at the ClusterIP address level.

  • ✗

    Service of type ClusterIP

    Why it's wrong here

    ClusterIP is the default Service type that creates a stable virtual IP internal to the cluster, reachable only from within the cluster (for example, by other Pods or Services). It cannot accept traffic from outside the cluster, so it is used for internal microservice communication and does not meet the requirement of exposing a set of pods externally.

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.