Courseiva
Services and Networking →mediumMultiple Select

CKA Services and Networking Practice Question

Which TWO statements about Ingress in Kubernetes are correct?

⚠ Common exam trap

Watch out — candidates often confuse Ingress's Layer 7 capabilities with Layer 4 load balancing, or assume gRPC works out-of-the-box without understanding that Ingress controllers require explicit HTTP/2 support and protocol configuration for gRPC.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ingress can terminate TLS connections for backend Services.

Option B is correct because an Ingress resource can reference a TLS Secret via spec.tls, allowing the Ingress controller to terminate TLS connections and forward decrypted HTTP traffic to the backend Services. Option E is correct because Ingress rules use the host field to match the HTTP Host header and route requests to different backend Services accordingly. Option A is wrong because spec.ingressClassName selects which Ingress controller should handle the resource; it does not disable the default controller. Option C is wrong because gRPC support is not native to Ingress and typically requires controller-specific annotations or a Gateway API/HTTPRoute setup. Option D is wrong because Ingress operates at Layer 7 (HTTP/HTTPS), while Layer 4 TCP/UDP load balancing requires a Service of type LoadBalancer or a Gateway API TCPRoute.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Setting spec.ingressClassName to 'nginx' disables the default Ingress controller.

    Why it's wrong here

    Setting spec.ingressClassName to a value like 'nginx' selects an IngressClass resource that identifies which Ingress controller should implement this Ingress. It does not disable the default controller; rather, it explicitly chooses among multiple installed controllers. If the named IngressClass is missing or lacks a controller, that Ingress may be ignored, but other Ingress resources remain unaffected.

  • ✓

    Ingress can terminate TLS connections for backend Services.

    Why this is correct

    Ingress can terminate TLS connections for backend Services when a TLS block specifies a secret containing a certificate and private key. The Ingress controller decrypts HTTPS traffic at the edge and forwards plain HTTP to the backend Service. This offloads TLS handling from application Pods and centralizes certificate management.

  • ✗

    Ingress natively supports gRPC services without any additional configuration.

    Why it's wrong here

    While Ingress operates at Layer 7, gRPC is not natively supported out of the box without additional configuration. gRPC relies on HTTP/2 framing, and many Ingress controllers require explicit enabling of HTTP/2, appropriate annotations, or a dedicated gRPC-aware load balancer. Simply deploying a gRPC service behind a default Ingress may fail or prevent streaming features from working.

  • ✗

    Ingress can provide Layer 4 (TCP/UDP) load balancing.

    Why it's wrong here

    Ingress is a Layer 7 resource that routes HTTP/HTTPS traffic based on hostnames and paths; it does not provide Layer 4 TCP/UDP load balancing. For TCP or UDP traffic, you need a Service of type LoadBalancer, a Network Load Balancer, or a controller specifically configured for TCP/UDP proxying. Ingress cannot forward raw connections or perform IP-level load balancing.

  • ✓

    Ingress can route traffic to different Services based on the hostname in the HTTP Host header.

    Why this is correct

    Ingress can route traffic to different backend Services based on the hostname in the HTTP Host header by defining multiple rules with distinct host fields. The Ingress controller inspects the Host header of each request and dispatches it to the Service specified for that host. This is known as name-based virtual hosting and is a standard feature of Ingress.

Go deeper

Related to this question

About these practice questions

This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.