CKA Services and Networking Practice Question
Which resource is used to configure TLS termination and path-based routing for HTTP(S) traffic into a cluster?
⚠ Common exam trap
CNCF often tests the distinction between Ingress and Service, where candidates mistakenly think a Service can handle TLS termination or path-based routing, but a Service only provides layer 4 load balancing without HTTP awareness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ingress
An Ingress resource provides HTTP and HTTPS routing to services within a Kubernetes cluster, enabling TLS termination and path-based routing. It acts as a layer 7 load balancer, directing external traffic to the appropriate backend Service based on hostnames and paths defined in its rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ingress
Why this is correct
Ingress is the standard Kubernetes resource designed specifically to manage external access to services, typically via HTTP/HTTPS. It natively supports TLS termination by referencing a TLS Secret and allows operators to define complex path-based or host-based routing rules to direct traffic to different backend Services.
- ✗
Service
Why it's wrong here
A Service operates primarily at Layer 4 (TCP/UDP) to provide stable IP addresses and load balancing across a set of Pods. It lacks the Layer 7 application-layer awareness required to inspect HTTP request paths or manage SSL/TLS handshakes and certificates.
- ✗
NetworkPolicy
Why it's wrong here
NetworkPolicies function as a firewall within the cluster, regulating traffic flow between Pods and external endpoints based on IP blocks, namespaces, and port numbers. They do not possess the capability to parse HTTP headers, evaluate URL paths, or terminate TLS encryption.
- ✗
Gateway
Why it's wrong here
While the newer Gateway API (comprising Gateway and HTTPRoute resources) is designed to succeed Ingress, it is an evolutionary, custom resource definition (CRD) based framework rather than the classic, built-in Kubernetes resource traditionally used for this purpose. In standard CKA contexts, Ingress remains the primary built-in API resource for path routing and TLS configuration.
Go deeper
Related to this question
Learn chapter
Kubernetes Architecture Overview
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.