CKA Services and Networking Practice Question
Which TWO of the following are components of the Ingress API? (Select TWO.)
⚠ Common exam trap
The CKA exam often tests the distinction between fields within the Ingress spec (like `rules` and `tls`) versus separate Kubernetes resources that are referenced by Ingress (like `IngressClass`, `Service`, and `Endpoints`), causing candidates to confuse API components with related but distinct objects.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
rules
Option A, rules, is correct because the Ingress spec is fundamentally built around a list of rules that map incoming HTTP/HTTPS host and path requests to backend Services, making rules a core component of the Ingress API. Option E, tls, is correct because the Ingress resource includes a tls field that declares TLS configuration (hosts and secretName) so the ingress controller can terminate TLS for specified hosts. IngressClass (B) is a separate API resource used to select which controller implements an Ingress, not a component inside the Ingress object itself. Service (C) and Endpoints (D) are distinct core/v1 resources that Ingress rules reference as backends; they are not part of the Ingress API's own structure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
rules
Why this is correct
The `rules` field is the core routing engine of the Ingress API; each rule defines an optional hostname and a list of HTTP paths, and each path has an associated `pathType` and a `backend` that references a Service name and port. When a request arrives, the Ingress controller evaluates these rules in order and forwards traffic to the specified backend, making rules the fundamental component for host- and path-based traffic routing.
- ✗
IngressClass
Why it's wrong here
`IngressClass` is a separate, cluster-level resource (in `networking.k8s.io/v1`) that describes the controller that should implement the Ingress, along with optional parameters and a default class. The Ingress spec itself does not contain an IngressClass object; it only has an optional `ingressClassName` field that references an IngressClass by name. Thus, IngressClass is a companion resource used for controller selection, not a structural component of the Ingress API spec.
- ✗
Service
Why it's wrong here
A `Service` is a distinct networking resource in Kubernetes that provides a stable virtual IP and DNS name for a set of pods. In the Ingress API, a Service is referenced only as the target backend for a rule or the default backend, identified by `service.name` and `service.port.number` or `name`. Service is a separate object from Ingress and is not a field or subresource of the Ingress spec, even though it is essential for the routing to ultimately reach pods.
- ✗
Endpoints
Why it's wrong here
`Endpoints` are automatically maintained by Kubernetes for each Service, holding the actual IP addresses of healthy pods selected by the Service's selector. They are never defined or configured inside an Ingress object; the Ingress controller resolves the referenced Service and uses its Endpoints to forward traffic. Since Endpoints are generated and consumed behind the scenes, they are not a component of the Ingress API itself.
- ✓
tls
Why this is correct
The `tls` field is a mandatory-in-context but optional component of the Ingress spec that configures Transport Layer Security (TLS) termination. It contains a list of TLS entries, each with a `hosts` array and a `secretName` pointing to a Kubernetes Secret that holds the TLS certificate and private key. When specified, the Ingress controller uses these settings to serve HTTPS for the listed hosts, making `tls` a core part of the Ingress API alongside `rules`.
Go deeper
Related to this question
Learn chapter
Troubleshooting Networking and Services
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
Ingress Controller
An Ingress Controller is a specialized component that manages external access to services in a Kubernetes cluster by processing Ingress resources and routing traffic according to defined rules.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.