CKA Services and Networking Practice Question
Which two of the following are valid methods for exposing a Service externally in Kubernetes? (Select TWO.)
⚠ Common exam trap
A common misconception is that Headless or ExternalName can expose a Service externally, but they are designed for internal DNS resolution and DNS aliasing, respectively, not for external traffic routing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
LoadBalancer
Option C (LoadBalancer) is correct because a Service of type LoadBalancer provisions an external load balancer (via the cloud provider's controller, e.g., an AWS ELB or GCP LB) that exposes the Service on a publicly reachable IP, making it externally accessible. Option D (NodePort) is correct because it allocates a static port on every node's IP (default range 30000-32767) and forwards traffic to the Service, so external clients can reach the Service via <NodeIP>:<NodePort>. Option A (Headless) is not a valid external exposure method; a headless Service (clusterIP: None) simply returns pod IPs directly via DNS for direct pod addressing, not external access. Option B (ExternalName) maps a Service to an external DNS name via a CNAME record and is used for accessing external resources from inside the cluster, not for exposing an internal Service externally. Option E (ClusterIP) is the default type and only provides an internal virtual IP reachable within the cluster, so it does not expose the Service externally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Headless
Why it's wrong here
A headless Service (clusterIP: None) does not provide a stable virtual IP or load balancing; it returns the DNS A/AAAA records of the backing pods, enabling direct pod-to-pod DNS resolution. Because it deliberately skips kube-proxy and the cluster IP allocation, it cannot expose the Service to external clients, so it's incorrect for external exposure.
- ✗
ExternalName
Why it's wrong here
An ExternalName Service maps a Service name to a CNAME record pointing at an external DNS name (e.g., a database outside the cluster). It does not create any selectors, endpoints, or cluster IP, and it simply returns a CNAME response, so it never exposes anything inside the cluster to external users.
- ✓
LoadBalancer
Why this is correct
A LoadBalancer Service is the standard way to expose a Service to the internet on a cloud provider; it provisions an external load balancer (e.g., AWS ELB, GCP LB) that forwards traffic to the Service's node ports or internal endpoints. This gives a stable external IP and L4 load balancing, making it one of the two valid methods for external exposure (along with NodePort).
- ✓
NodePort
Why this is correct
A NodePort Service exposes the Service on a static port (30000-32767) on every node's IP address, allowing external traffic to reach the Service by contacting any node at that port. It is a valid method for external exposure, often used for on-premises or as a building block for cloud load balancers.
- ✗
ClusterIP
Why it's wrong here
A ClusterIP Service is the default type that exposes the Service only on a cluster-internal IP address; it is reachable only from within the cluster and cannot be accessed from outside without an ingress, NodePort, or LoadBalancer. Since it is internal-only, it is not a valid method for exposing the Service externally.
Visual reference
Go deeper
Related to this question
Learn chapter
Troubleshooting Cluster and Node Issues
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
Key term
ClusterIP NodePort LoadBalancer
ClusterIP, NodePort, and LoadBalancer are three types of Kubernetes Services that control how traffic reaches your application pods inside the cluster or from outside.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.