CKA Troubleshooting Practice Question
You are tasked with troubleshooting a production Kubernetes cluster. A user reports that they cannot access a web application running in the cluster. The application is deployed as a Deployment named 'frontend' with 2 replicas, exposed via a Service of type LoadBalancer. You have kubectl access to the cluster. You run 'kubectl get pods -l app=frontend' and see both pods are Running and Ready. You run 'kubectl get svc frontend' and see the Service has an external IP of 192.168.1.100. However, when you curl http://192.168.1.100 from a machine outside the cluster, you get a connection timeout. You are able to curl the pod IPs directly from within the cluster and get a response. Which of the following is the most likely cause of the issue?
⚠ Common exam trap
It's easy for candidates to assume a LoadBalancer Service automatically works end-to-end, but the CKA exam tests the understanding that cloud provider integration (security groups, load balancer health checks) is a separate layer that can fail even when Kubernetes components are healthy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The cloud provider's load balancer is not properly configured or the security group/firewall is blocking traffic to the node ports.
The pods are running and ready, and the service has an external IP, but external access fails with a connection timeout while internal access to pod IPs works. This indicates the cloud provider's load balancer is not properly routing traffic to the node ports, or a security group/firewall is blocking inbound traffic on the node port range (30000-32767). The load balancer must forward traffic to the node ports, and the nodes must allow that traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Service selector does not match the pod labels.
Why it's wrong here
If the Service selector did not match the Pod labels, the Kubernetes control plane would fail to populate the Service's Endpoints object. Consequently, internal traffic to the Service IP would also fail, which contradicts the scenario where internal access succeeds.
- ✓
The cloud provider's load balancer is not properly configured or the security group/firewall is blocking traffic to the node ports.
Why this is correct
When internal cluster communication works but external traffic times out, the issue lies in the external network path. Misconfigured cloud load balancers or restrictive security groups/firewalls blocking the NodePort range (typically 30000-32767) prevent external packets from reaching the cluster nodes.
- ✗
The NodePort service type is not enabled in the cluster.
Why it's wrong here
NodePort is a standard, built-in Kubernetes Service type that is enabled by default in all compliant clusters. Furthermore, a LoadBalancer service automatically provisions and builds upon NodePort functionality under the hood, meaning NodePort does not need to be independently enabled.
- ✗
The Ingress resource is missing or misconfigured.
Why it's wrong here
A Service of type LoadBalancer exposes applications directly to the internet via a cloud provider's network load balancer. It operates independently of an Ingress resource, which is a separate API object used for HTTP/HTTPS routing and requires an Ingress controller to function.
Go deeper
Related to this question
Learn chapter
Kubernetes Architecture Overview
Key term
kubectl Command Reference
kubectl is the command-line tool used to interact with and manage Kubernetes clusters by sending commands to the Kubernetes API.
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.