Courseiva
Services and Networking →mediumMultiple Select

CKA Services and Networking Practice Question

Which TWO statements are true about Ingress in Kubernetes?

⚠ Common exam trap

This certification often tests the misconception that IngressClass is mandatory or that Ingress can function without a controller, leading candidates to overestimate the Ingress resource's autonomy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ingress can terminate TLS connections

Option A is correct because an Ingress resource can specify a TLS block with a secretName referencing a Kubernetes TLS Secret, allowing the Ingress controller to terminate TLS connections at the edge before forwarding traffic to backend Services. Option B is correct because a single Ingress resource can define multiple rules and paths (host- and path-based routing) that map to different backend Services, all reachable through the same Ingress controller IP address. Option C is not correct because IngressClass is not a mandatory field in the Ingress spec; it can be set via the ingressClassName field or the deprecated kubernetes.io/ingress.class annotation, and defaults may apply. Option D is not correct because Services can also be exposed externally via NodePort, LoadBalancer, or externalIPs without using Ingress. Option E is not correct because an Ingress resource has no effect on its own; an Ingress controller (such as NGINX or Traefik) must be running to implement the routing rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Ingress can terminate TLS connections

    Why this is correct

    Ingress can terminate TLS because the Ingress spec supports a tls section that references a Secret containing the certificate and private key. When configured, the Ingress controller performs HTTPS termination, decrypting traffic at the edge and forwarding plain HTTP to backend Services. This is a built-in feature of most controllers, such as NGINX, and is managed by the controller itself.

  • ✓

    Ingress can expose multiple Services under the same IP address

    Why this is correct

    Ingress can route traffic for multiple Services through a single external IP address by using virtual hosting rules based on the request host header and URL path. The controller inspects each incoming request and forwards it to the appropriate backend Service according to the rules defined in the Ingress resource. This eliminates the need for a separate LoadBalancer or NodePort per Service.

  • ✗

    IngressClass is a mandatory field in Ingress spec

    Why it's wrong here

    The IngressClass is not mandatory in the Ingress spec because if the ingressClassName field is omitted, the cluster's default IngressClass will be used. Administrators can also set a default IngressClass by adding the ingressclass.kubernetes.io/is-default-class annotation, making the explicit field unnecessary. Thus, omitting it does not invalidate the Ingress resource.

  • ✗

    Ingress is the only way to expose Services externally

    Why it's wrong here

    Ingress is not the only way to expose Services externally because Services can be published directly with NodePort, which opens a static port on every node, or with LoadBalancer, which provisions a cloud load balancer. These methods provide external access to Services without any Ingress resource or controller. Therefore, Ingress is one of several options, not the sole mechanism.

  • ✗

    Ingress works without an Ingress controller

    Why it's wrong here

    An Ingress resource is merely a set of routing rules and does not implement any traffic forwarding by itself. An Ingress controller, such as NGINX, HAProxy, or Traefik, must be deployed in the cluster to read those rules, configure the actual proxy, and manage the load balancer. Without a controller, creating an Ingress object has no effect on external access to Services.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.