CKA Services and Networking Practice Question
Which three components are part of the Gateway API? (Choose three.)
⚠ Common exam trap
The CKA exam often tests the distinction between the older Ingress API and the newer Gateway API, where candidates mistakenly think Ingress is a component of the Gateway API, but Ingress is a separate, standalone resource.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GatewayClass
The Gateway API defines three core resource types: GatewayClass, Gateway, and HTTPRoute (along with other route types like TCPRoute and TLSRoute). Option B, GatewayClass, is correct because it is a cluster-scoped resource that identifies the controller implementing the Gateway API and defines the class of gateways available. Option C, Gateway, is correct because it represents an instance of a gateway that provisions the underlying load balancer or proxy and defines listeners for traffic. Option D, HTTPRoute, is correct because it is a route resource that attaches to a Gateway and specifies how HTTP traffic is matched and forwarded to backend Services. Option A, Ingress, is not part of the Gateway API; it is a separate, older Kubernetes API for HTTP routing. Option E, Service, is a core Kubernetes resource used as a backend target, not a component of the Gateway API itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ingress
Why it's wrong here
Ingress is a separate, older Kubernetes API, not a component of the Gateway API. While both expose HTTP routing, Ingress is a distinct resource with its own spec, controller, and limitations. The Gateway API was designed to address Ingress's shortcomings like limited expressiveness and poor portability, but it never includes Ingress itself. Thus, Ingress is incorrect because it is a predecessor, not one of the three core Gateway API resources.
- ✓
GatewayClass
Why this is correct
GatewayClass is one of the three core Gateway API resources and serves as a cluster-scoped template that defines a named class of gateways. It references a controller that manages gateways of that class and can include parameters for customization, similar to StorageClass in the storage API. By grouping gateways into classes, it enables different implementations (e.g., different load balancers) to be used transparently within the same cluster. Thus, GatewayClass is correct because it is a fundamental building block for defining gateway behavior.
- ✓
Gateway
Why this is correct
Gateway is one of the three core Gateway API resources and represents the abstracted load balancer or proxy that handles incoming traffic. It is a namespaced resource that references a GatewayClass and declares listener configurations, such as hostnames, ports, and protocols. The Gateway resource is the point of entry for requests, acting as the actual runtime instance of the infrastructure. It is correct because it defines the concrete entry point for network traffic in the Gateway API model.
- ✓
HTTPRoute
Why this is correct
HTTPRoute is one of the three core Gateway API resources and is used to define routing rules for HTTP traffic. It is a namespaced resource that matches requests based on hostnames, headers, or other attributes and forwards them to specified backends, such as Services. HTTPRoute enables fine-grained control, including traffic splitting, retries, and timeouts, which are not natively available in Ingress. It is correct because it is the core resource for routing HTTP traffic in the Gateway API.
- ✗
Service
Why it's wrong here
Service is a core Kubernetes API resource used to expose pods as a network service, providing stable IP addresses and DNS names. It is not part of the Gateway API, which defines a separate hierarchy of resources (GatewayClass, Gateway, and HTTPRoute) for ingress traffic management. Services are often used as backend targets for Gateway API routes, but they are not themselves components of the Gateway API. Therefore, Service is incorrect because it belongs to the older core network API model, not to the Gateway API's resource set.
Go deeper
Related to this question
Learn chapter
Installing Kubernetes with kubeadm
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.