CKA Services and Networking Practice Question
Which resource type is used to configure HTTP/HTTPS routing to Services?
⚠ Common exam trap
It's easy for candidates to confuse a Service's external exposure (e.g., NodePort or LoadBalancer) with the need for HTTP/HTTPS routing, forgetting that Ingress is the dedicated resource for L7 routing and TLS termination.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ingress
Ingress is the Kubernetes resource that provides HTTP and HTTPS routing from outside the cluster to Services within the cluster. It defines rules for host-based and path-based routing, TLS termination, and load balancing, making it the correct choice for configuring external HTTP/HTTPS access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
EndpointSlice
Why it's wrong here
EndpointSlice is a scalable resource used by Kubernetes to track the individual IP addresses, ports, and readiness states of backend Pods. While it provides the crucial mapping data that Services and Ingress controllers use to locate healthy endpoints, it does not perform any Layer 7 HTTP/HTTPS routing or rule evaluation itself.
- ✗
NetworkPolicy
Why it's wrong here
NetworkPolicy acts as a firewall at the IP address or port level (Layer 3 and Layer 4) to control ingress and egress traffic flow between Pods and external networks. It is used to enforce security boundaries and isolate workloads, but it lacks the capability to inspect application-layer headers, paths, or hostnames to route HTTP/HTTPS traffic.
- ✓
Ingress
Why this is correct
Ingress is the standard Kubernetes API resource designed specifically to manage external access to services, typically via HTTP and HTTPS. It allows administrators to define routing rules based on hostnames (Layer 7 domain names) and URL paths, enabling a single external IP address to expose multiple backend services.
- ✗
Service
Why it's wrong here
A Service is a Layer 4 abstraction that provides a stable IP address and DNS name to load-balance TCP/UDP traffic across a set of Pods. Although it exposes workloads to the network, it cannot parse application-layer protocols to route traffic based on HTTP headers, cookies, or URL paths.
Go deeper
Related to this question
Learn chapter
Troubleshooting Networking and Services
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.