CKA Services and Networking Practice Question
Which TWO commands can be used to test DNS resolution for a Service named 'my-svc' in namespace 'default' from within a temporary pod? (Choose 2)
⚠ Common exam trap
The CKA exam often tests the distinction between tools that perform DNS resolution (nslookup, dig) versus tools that test network connectivity (wget, curl, ping), leading candidates to mistakenly choose connectivity tools for DNS testing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl run test --image=busybox --rm -it --restart=Never -- nslookup my-svc
Option B is correct because nslookup is a DNS query tool included in busybox that resolves the Service name 'my-svc' to its ClusterIP by querying the cluster DNS (CoreDNS), directly testing DNS resolution from inside a temporary busybox pod. Option E is incorrect because the standard busybox image does not include dig; the command would fail with 'dig: not found'. To use dig, you must use an image that contains it, such as gcr.io/kubernetes-e2e-test-images/dnsutils:1.3. Options A and D are incorrect because wget and curl are HTTP clients that test connectivity to a web endpoint, not DNS resolution itself, and they would fail if the Service has no HTTP listener. Option C is incorrect because ping tests ICMP reachability, not DNS resolution, and many Service ClusterIPs do not respond to ICMP even when DNS works.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl run test --image=busybox --rm -it --restart=Never -- wget my-svc
Why it's wrong here
wget tests HTTP, not DNS.
- ✓
kubectl run test --image=busybox --rm -it --restart=Never -- nslookup my-svc
Why this is correct
nslookup queries DNS.
- ✗
kubectl run test --image=busybox --rm -it --restart=Never -- ping my-svc
Why it's wrong here
ping tests ICMP connectivity, not DNS.
- ✗
kubectl run test --image=busybox --rm -it --restart=Never -- curl my-svc
Why it's wrong here
curl tests HTTP, not DNS resolution directly.
- ✗
kubectl run test --image=busybox --rm -it --restart=Never -- dig my-svc
Why it's wrong here
dig also queries DNS.
Visual reference
Go deeper
Related to this question
Learn chapter
Network Policies and Secure Connectivity
Key term
ClusterIP NodePort LoadBalancer
ClusterIP, NodePort, and LoadBalancer are three types of Kubernetes Services that control how traffic reaches your application pods inside the cluster or from outside.
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.