Courseiva
Services and Networking →mediumMultiple Select

CKA Services and Networking Practice Question

Which THREE of the following are valid methods for service discovery in Kubernetes?

⚠ Common exam trap

Many exam-takers confuse `kubectl port-forward` (a manual, ephemeral tunnel) with a built-in discovery mechanism, or mistake Ingress (external routing) for internal service-to-service communication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Environment variables (e.g., SERVICE_NAME_SERVICE_HOST)

Environment variables (B) are a valid service-discovery mechanism because kubelet injects variables such as SERVICE_NAME_SERVICE_HOST and SERVICE_NAME_SERVICE_PORT for each Service into Pods at creation time, letting containers locate dependencies without an external registry. DNS lookups using CoreDNS (D) are the canonical discovery method: CoreDNS serves records like <service>.<namespace>.svc.cluster.local and SRV records for named ports, resolving Service ClusterIPs and headless endpoints. Kubernetes API queries (E) are valid because clients can list/watch Service and Endpoints/EndpointSlice objects via kubectl or direct API calls to discover backends dynamically. kubectl port-forward (A) merely tunnels a local port to a Pod or Service for debugging and does not provide in-cluster discovery, while Ingress rules (C) only expose HTTP/HTTPS routes from outside the cluster and are not a discovery mechanism for workloads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl port-forward

    Why it's wrong here

    kubectl port-forward tunnels a local port to a single Pod for debugging; it creates no cluster-wide discoverable Service endpoint. It is tempting because it lets you reach a workload by name during troubleshooting, and it would be correct for temporary local access to a Pod, not for service discovery between workloads.

  • ✓

    Environment variables (e.g., SERVICE_NAME_SERVICE_HOST)

    Why this is correct

    Kubernetes injects environment variables for each active Service into pod containers, exposing values such as SERVICE_NAME_SERVICE_HOST. This lets applications discover service endpoints without querying DNS or the API, satisfying the stem's valid service discovery methods.

  • ✗

    Ingress rules

    Why it's wrong here

    Ingress rules route external HTTP traffic to Services; they do not provide the Service-to-Pod endpoint discovery mechanism itself. It is tempting because Ingress exposes applications by name, which resembles discovery, and it would be the right choice for publishing an HTTP service externally rather than for internal service discovery.

  • ✓

    DNS lookups using CoreDNS

    Why this is correct

    CoreDNS runs as a cluster DNS add-on, resolving Service names to ClusterIPs so pods reach backends by name rather than hard-coded addresses. This satisfies the stem's requirement for a valid service discovery method, since Kubernetes natively supports DNS-based lookups for both Services and headless Services.

  • ✓

    Kubernetes API queries via kubectl or API calls

    Why this is correct

    Applications can query the Kubernetes API server directly, via kubectl or client libraries, to list Services and Endpoints objects. This programmatic lookup returns current endpoint addresses, satisfying the stem's requirement for a valid service discovery method.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.