Courseiva
Services and Networking →mediumMultiple Select

CKA Services and Networking Practice Question

Which TWO commands can be used to test DNS resolution for a Service named 'my-svc' in namespace 'default' from within a temporary pod? (Choose 2)

⚠ Common exam trap

The CKA exam often tests the distinction between tools that perform DNS resolution (nslookup, dig) versus tools that test network connectivity (wget, curl, ping), leading candidates to mistakenly choose connectivity tools for DNS testing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl run test --image=busybox --rm -it --restart=Never -- nslookup my-svc

Option B is correct because nslookup is a DNS query tool included in busybox that resolves the Service name 'my-svc' to its ClusterIP by querying the cluster DNS (CoreDNS), directly testing DNS resolution from inside a temporary busybox pod. Option E is incorrect because the standard busybox image does not include dig; the command would fail with 'dig: not found'. To use dig, you must use an image that contains it, such as gcr.io/kubernetes-e2e-test-images/dnsutils:1.3. Options A and D are incorrect because wget and curl are HTTP clients that test connectivity to a web endpoint, not DNS resolution itself, and they would fail if the Service has no HTTP listener. Option C is incorrect because ping tests ICMP reachability, not DNS resolution, and many Service ClusterIPs do not respond to ICMP even when DNS works.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl run test --image=busybox --rm -it --restart=Never -- wget my-svc

    Why it's wrong here

    wget tests HTTP, not DNS.

  • ✓

    kubectl run test --image=busybox --rm -it --restart=Never -- nslookup my-svc

    Why this is correct

    nslookup queries DNS.

  • ✗

    kubectl run test --image=busybox --rm -it --restart=Never -- ping my-svc

    Why it's wrong here

    ping tests ICMP connectivity, not DNS.

  • ✗

    kubectl run test --image=busybox --rm -it --restart=Never -- curl my-svc

    Why it's wrong here

    curl tests HTTP, not DNS resolution directly.

  • ✗

    kubectl run test --image=busybox --rm -it --restart=Never -- dig my-svc

    Why it's wrong here

    dig also queries DNS.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.