Courseiva
Services and Networking →mediumMultiple Select

CKA Services and Networking Practice Question

Which TWO of the following are components of the Ingress API? (Select TWO.)

⚠ Common exam trap

The CKA exam often tests the distinction between fields within the Ingress spec (like `rules` and `tls`) versus separate Kubernetes resources that are referenced by Ingress (like `IngressClass`, `Service`, and `Endpoints`), causing candidates to confuse API components with related but distinct objects.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

rules

Option A, rules, is correct because the Ingress spec is fundamentally built around a list of rules that map incoming HTTP/HTTPS host and path requests to backend Services, making rules a core component of the Ingress API. Option E, tls, is correct because the Ingress resource includes a tls field that declares TLS configuration (hosts and secretName) so the ingress controller can terminate TLS for specified hosts. IngressClass (B) is a separate API resource used to select which controller implements an Ingress, not a component inside the Ingress object itself. Service (C) and Endpoints (D) are distinct core/v1 resources that Ingress rules reference as backends; they are not part of the Ingress API's own structure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    rules

    Why this is correct

    The `rules` field is the core routing engine of the Ingress API; each rule defines an optional hostname and a list of HTTP paths, and each path has an associated `pathType` and a `backend` that references a Service name and port. When a request arrives, the Ingress controller evaluates these rules in order and forwards traffic to the specified backend, making rules the fundamental component for host- and path-based traffic routing.

  • ✗

    IngressClass

    Why it's wrong here

    `IngressClass` is a separate, cluster-level resource (in `networking.k8s.io/v1`) that describes the controller that should implement the Ingress, along with optional parameters and a default class. The Ingress spec itself does not contain an IngressClass object; it only has an optional `ingressClassName` field that references an IngressClass by name. Thus, IngressClass is a companion resource used for controller selection, not a structural component of the Ingress API spec.

  • ✗

    Service

    Why it's wrong here

    A `Service` is a distinct networking resource in Kubernetes that provides a stable virtual IP and DNS name for a set of pods. In the Ingress API, a Service is referenced only as the target backend for a rule or the default backend, identified by `service.name` and `service.port.number` or `name`. Service is a separate object from Ingress and is not a field or subresource of the Ingress spec, even though it is essential for the routing to ultimately reach pods.

  • ✗

    Endpoints

    Why it's wrong here

    `Endpoints` are automatically maintained by Kubernetes for each Service, holding the actual IP addresses of healthy pods selected by the Service's selector. They are never defined or configured inside an Ingress object; the Ingress controller resolves the referenced Service and uses its Endpoints to forward traffic. Since Endpoints are generated and consumed behind the scenes, they are not a component of the Ingress API itself.

  • ✓

    tls

    Why this is correct

    The `tls` field is a mandatory-in-context but optional component of the Ingress spec that configures Transport Layer Security (TLS) termination. It contains a list of TLS entries, each with a `hosts` array and a `secretName` pointing to a Kubernetes Secret that holds the TLS certificate and private key. When specified, the Ingress controller uses these settings to serve HTTPS for the listed hosts, making `tls` a core part of the Ingress API alongside `rules`.

Go deeper

Related to this question

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.