Courseiva
Troubleshooting →hardMultiple Select

CKA Troubleshooting Practice Question

Which THREE of the following are valid commands to troubleshoot network connectivity between pods? (Select 3)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl exec pod-a -- nslookup service-name

kubectl exec can run networking tools inside a pod. curl is a common tool. nslookup tests DNS. ping tests basic connectivity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    kubectl exec pod-a -- nslookup service-name

    Why this is correct

    This command launches nslookup inside pod-a's network namespace, querying the cluster's CoreDNS/kube-dns service to resolve the name "service-name". Successful resolution proves that DNS pod(s), kube-dns service, and the pod's resolv.conf are functioning, and it returns the ClusterIP or headless endpoints needed for service discovery. It is a valid connectivity test because without DNS, application-level communication via service names fails regardless of reachable pods.

  • ✗

    kubectl describe node | grep Network

    Why it's wrong here

    kubectl describe node fetches the Node object's status and metadata, and piping to grep Network simply isolates lines containing the word "Network," such as pod CIDR assignments or the internal IP field. This is a static snapshot of node configuration, not an active probe: it cannot tell you whether packets can actually traverse the CNI, whether a remote pod is listening, or if network policies permit traffic. Therefore it does not test pod-to-pod connectivity and is not a valid troubleshooting command for this scenario.

  • ✗

    kubectl logs pod-a | grep network

    Why it's wrong here

    kubectl logs pod-a streams the container's captured stdout/stderr from its runtime; grepping "network" merely filters those log lines for the literal string, which may reveal application-level errors if the app logs network failures. However, it generates no traffic, sends no packets to another pod, and cannot test reachability, DNS, routing, or service connectivity. At best it is a passive observation aid, so it is not a valid command to actively troubleshoot network connectivity between pods.

  • ✓

    kubectl exec pod-a -- curl http://pod-b

    Why this is correct

    This command uses kubectl exec to run curl inside pod-a and sends an HTTP request to http://pod-b, where pod-b is either a service name or a resolvable pod address. It actively traverses the pod network, verifies L3/L4 reachability, confirms the destination container is listening, and yields an HTTP status code that reflects the application's health. Because service names may not be resolvable from within a pod unless DNS is configured correctly, this also tests DNS and service routing, making it a high-value troubleshooting tool.

  • ✓

    kubectl exec pod-a -- ping pod-b-ip

    Why this is correct

    Executing ping pod-b-ip from inside pod-a sends ICMP echo requests to the pod's IP address, testing raw L3/IP connectivity across the cluster's network without relying on DNS or application listeners. This is valid for verifying that the CNI is routing pod-to-pod traffic and that no network policy or firewall is dropping packets at the IP layer. However, ICMP is often blocked by network policies or cloud environments, so a failed ping does not definitively prove broken connectivity, while a successful ping only proves IP reachability, not that a service is ready.

About these practice questions

This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.