CKA Services and Networking Practice Question
Which TWO statements are true about Ingress in Kubernetes?
⚠ Common exam trap
This certification often tests the misconception that IngressClass is mandatory or that Ingress can function without a controller, leading candidates to overestimate the Ingress resource's autonomy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ingress can terminate TLS connections
Option A is correct because an Ingress resource can specify a TLS block with a secretName referencing a Kubernetes TLS Secret, allowing the Ingress controller to terminate TLS connections at the edge before forwarding traffic to backend Services. Option B is correct because a single Ingress resource can define multiple rules and paths (host- and path-based routing) that map to different backend Services, all reachable through the same Ingress controller IP address. Option C is not correct because IngressClass is not a mandatory field in the Ingress spec; it can be set via the ingressClassName field or the deprecated kubernetes.io/ingress.class annotation, and defaults may apply. Option D is not correct because Services can also be exposed externally via NodePort, LoadBalancer, or externalIPs without using Ingress. Option E is not correct because an Ingress resource has no effect on its own; an Ingress controller (such as NGINX or Traefik) must be running to implement the routing rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ingress can terminate TLS connections
Why this is correct
Ingress can terminate TLS because the Ingress spec supports a tls section that references a Secret containing the certificate and private key. When configured, the Ingress controller performs HTTPS termination, decrypting traffic at the edge and forwarding plain HTTP to backend Services. This is a built-in feature of most controllers, such as NGINX, and is managed by the controller itself.
- ✓
Ingress can expose multiple Services under the same IP address
Why this is correct
Ingress can route traffic for multiple Services through a single external IP address by using virtual hosting rules based on the request host header and URL path. The controller inspects each incoming request and forwards it to the appropriate backend Service according to the rules defined in the Ingress resource. This eliminates the need for a separate LoadBalancer or NodePort per Service.
- ✗
IngressClass is a mandatory field in Ingress spec
Why it's wrong here
The IngressClass is not mandatory in the Ingress spec because if the ingressClassName field is omitted, the cluster's default IngressClass will be used. Administrators can also set a default IngressClass by adding the ingressclass.kubernetes.io/is-default-class annotation, making the explicit field unnecessary. Thus, omitting it does not invalidate the Ingress resource.
- ✗
Ingress is the only way to expose Services externally
Why it's wrong here
Ingress is not the only way to expose Services externally because Services can be published directly with NodePort, which opens a static port on every node, or with LoadBalancer, which provisions a cloud load balancer. These methods provide external access to Services without any Ingress resource or controller. Therefore, Ingress is one of several options, not the sole mechanism.
- ✗
Ingress works without an Ingress controller
Why it's wrong here
An Ingress resource is merely a set of routing rules and does not implement any traffic forwarding by itself. An Ingress controller, such as NGINX, HAProxy, or Traefik, must be deployed in the cluster to read those rules, configure the actual proxy, and manage the load balancer. Without a controller, creating an Ingress object has no effect on external access to Services.
Go deeper
Related to this question
Learn chapter
Kubernetes Architecture Overview
Key term
ClusterIP NodePort LoadBalancer
ClusterIP, NodePort, and LoadBalancer are three types of Kubernetes Services that control how traffic reaches your application pods inside the cluster or from outside.
Key term
Ingress Controller
An Ingress Controller is a specialized component that manages external access to services in a Kubernetes cluster by processing Ingress resources and routing traffic according to defined rules.
About these practice questions
Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.