Courseiva
Services and Networking →mediumMultiple Select

CKA Services and Networking Practice Question

Which TWO of the following are valid ways to expose a Service externally in a Kubernetes cluster running on-premises (no cloud provider)?

⚠ Common exam trap

Watch out — candidates often assume Ingress is not a valid external exposure method because it is not a Service type, but the question asks for 'valid ways to expose a Service externally,' and Ingress achieves this by routing external traffic to internal Services, making it a correct answer alongside NodePort.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NodePort

NodePort (B) is correct because it exposes a Service on each node's IP at a static port in the 30000-32767 range, which works on any on-premises cluster without a cloud provider's load-balancer integration. Ingress (C) is correct because an Ingress resource plus an Ingress controller (e.g., NGINX, Traefik) provides HTTP/HTTPS routing from outside the cluster to internal Services, and it functions on-premises as long as the controller is deployed and reachable. LoadBalancer (A) is not valid here because it relies on a cloud provider's load-balancer implementation (or a bare-metal solution like MetalLB) to allocate an external IP, which is absent in a plain on-premises cluster. ClusterIP (D) only provides an internal virtual IP reachable within the cluster, so it does not expose the Service externally. ExternalName (E) merely returns a CNAME DNS record pointing to an external hostname and does not expose a Service running in the cluster.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    LoadBalancer

    Why it's wrong here

    While a LoadBalancer service type can expose services externally, it is considered invalid or impractical in bare-metal or non-cloud environments without an external controller like MetalLB. It relies heavily on cloud-provider integration to provision an external load balancer, making it a non-standard or highly dependent method for general service exposure.

  • ✓

    NodePort

    Why this is correct

    NodePort is a highly reliable, built-in method that allocates a static port (typically in the 30000-32767 range) across all cluster nodes. External traffic hitting any node's IP address on this designated port is automatically routed to the underlying target pods, making it a universally supported way to expose services.

  • ✓

    Ingress

    Why this is correct

    An Ingress resource, managed by an Ingress Controller like NGINX or Traefik, acts as an entry point that routes external HTTP and HTTPS traffic to internal cluster services. It provides advanced routing rules, SSL termination, and path-based routing, serving as a highly flexible and standard mechanism to expose multiple services under a single IP.

  • ✗

    ClusterIP

    Why it's wrong here

    ClusterIP is the default Kubernetes service type, but it only allocates an internal IP address that is reachable from within the cluster boundaries. It cannot be used to expose services to external clients or traffic originating outside the Kubernetes network, making it unsuitable for public-facing workloads.

  • ✗

    ExternalName

    Why it's wrong here

    ExternalName is a special service type that acts as an internal alias, mapping a local Kubernetes service name to an external DNS name via a CNAME record. It is designed to let internal pods access external resources easily, rather than exposing internal cluster workloads to external clients.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.