CKA Services and Networking Practice Question
You create a ClusterIP service named 'my-svc' in the 'default' namespace. A pod in the same namespace tries to reach the service using the DNS name 'my-svc'. Which fully qualified domain name (FQDN) should the pod use to resolve the service?
⚠ Common exam trap
The trap here is that candidates often forget the `svc` subdomain in the FQDN or omit the namespace, leading them to choose options like `my-svc.svc.cluster.local` (missing namespace) or `my-svc.default.cluster.local` (missing `svc`), while the correct format is `<service>.<namespace>.svc.cluster.local`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
my-svc.default.svc.cluster.local
The standard FQDN for a Kubernetes service in the default namespace is `<service-name>.<namespace>.svc.cluster.local`. This is the DNS record created by CoreDNS (or kube-dns) for ClusterIP services, allowing pods to resolve the service by its fully qualified domain name. The pod can also use the shorter form `my-svc` because the DNS search path includes the service's namespace and the `svc.cluster.local` suffix, but the FQDN ensures unambiguous resolution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
my-svc.default.svc.cluster
Why it's wrong here
This address is an incomplete FQDN because it ends with 'cluster' instead of 'cluster.local'. The default Kubernetes cluster domain is cluster.local, and the full service DNS name must include that entire suffix. Without the .local segment, the name falls outside the configured search domain in resolv.conf, so the glibc resolver will not append the correct suffix and the lookup will fail.
- ✓
my-svc.default.svc.cluster.local
Why this is correct
This is the canonical fully qualified domain name for a ClusterIP Service in the default namespace. Kubernetes DNS constructs it as <service-name>.<namespace>.svc.cluster.local, where 'svc' identifies the service record type and cluster.local is the cluster domain. When you create a Service named my-svc in the default namespace, this exact FQDN resolves to the Service's ClusterIP address, enabling stable in-cluster service discovery.
- ✗
my-svc.default.cluster.local
Why it's wrong here
This hostname omits the mandatory 'svc' subdomain, so it does not match the DNS record that Kubernetes generates for services. The actual service record is published under the namespace.svc.cluster.local subtree, not under the bare namespace.cluster.local subtree. A lookup for my-svc.default.cluster.local will either be handled by some other record or fail, but it will never resolve to my-svc's ClusterIP because the 'svc' label is a required structural component.
- ✗
my-svc.svc.cluster.local
Why it's wrong here
This hostname is missing the namespace component, making it impossible to identify which namespace the service belongs to. Services in Kubernetes are namespaced resources, so every service DNS name must include the namespace immediately before the 'svc' subdomain. Without 'default' in the FQDN, the name my-svc.svc.cluster.local is incomplete and will not match the actual DNS record for the service, even if the service is in the default namespace.
Visual reference
Go deeper
Related to this question
Learn chapter
Installing Kubernetes with kubeadm
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
CoreDNS
CoreDNS is a fast, flexible, and pluggable Domain Name System (DNS) server that is often used as the cluster DNS for Kubernetes, translating service names into IP addresses so containers can find each other.
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.