CKA Services & Networking Practice Question
You are tasked with troubleshooting a web application that is deployed in a Kubernetes cluster. The application consists of a Deployment named 'web-app' with 3 replicas, each running a container that listens on port 3000. A Service named 'web-service' of type ClusterIP with selector 'app: web' and port 80 targeting port 3000 has been created. Additionally, an Ingress resource named 'web-ingress' is configured with a host rule for 'example.com' and backend service 'web-service' on port 80. Users report that accessing http://example.com results in a 503 Service Unavailable error. You verify that all pods are running, but kubectl get pods shows the READY column as 0/1 for each pod. The Ingress controller logs show 'upstream connect error or disconnect/reset before headers'. You check the endpoints: 'kubectl get endpoints web-service' shows no endpoints. The pods have the label 'app: web'. What should you do to resolve the issue?
⚠ Common exam trap
The trap here is assuming that missing endpoints always mean a mismatched Service selector. If the pods are running but their READY status is 0/1, the endpoints will be empty because the readiness probe is failing, not because of a selector mismatch.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the container port and readiness probe configuration; the pods may not be listening on the expected port or the readiness probe is failing.
Although the Service's selector 'app: web' matches the pod labels, the absence of endpoints indicates that the pods are not being considered ready by the Service. Since `kubectl get pods` shows the READY column as '0/1', the readiness probes are failing or the container is not successfully listening on the expected port. This prevents the endpoints controller from adding the pod IPs to the Service's Endpoints list. Checking the container port and readiness probe configuration is the correct troubleshooting step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the Service type to NodePort to bypass the Ingress.
Why it's wrong here
Changing Service type does not affect endpoint creation; the root cause is missing endpoints.
- ✗
Update the Ingress to use a different backend service.
Why it's wrong here
The Ingress is correctly configured; the issue is with the Service itself.
- ✓
Check the container port and readiness probe configuration; the pods may not be listening on the expected port or the readiness probe is failing.
Why this is correct
Empty endpoints indicate no ready pods matching the selector; despite 'Ready' status, the readiness probe might be failing if not configured, or the container might not be listening on 3000.
- ✗
Modify the Service selector to match the pod labels exactly.
Why it's wrong here
The selector already matches 'app: web'; this would not change anything.
Visual reference
Go deeper
Related to this question
Learn chapter
Kubernetes Architecture Overview
Key term
ClusterIP NodePort LoadBalancer
ClusterIP, NodePort, and LoadBalancer are three types of Kubernetes Services that control how traffic reaches your application pods inside the cluster or from outside.
Key term
kubectl Command Reference
kubectl is the command-line tool used to interact with and manage Kubernetes clusters by sending commands to the Kubernetes API.
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.