CKA Services and Networking Practice Question
You have a Service 'my-svc' with ClusterIP None (headless). You create a StatefulSet with 3 replicas and a headless Service. How do you reach individual pods?
⚠ Common exam trap
It's easy for candidates to assume a Service always provides a virtual IP for load balancing, but a headless Service deliberately removes that abstraction to expose individual pod identities directly via DNS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the pod DNS name: <pod-name>.my-svc.<namespace>.svc.cluster.local
In a headless Service (ClusterIP: None), Kubernetes creates DNS A/AAAA records for each pod in a StatefulSet using the pattern <pod-name>.<service-name>.<namespace>.svc.cluster.local. This allows direct, stable network identity for each pod, which is essential for stateful applications like databases that require consistent hostnames.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use the pod DNS name: <pod-name>.my-svc.<namespace>.svc.cluster.local
Why this is correct
When a Service is configured as headless by setting clusterIP to None, CoreDNS automatically creates individual A or AAAA records for each backing Pod that matches the selector. These records are formatted as <pod-name>.<service-name>.<namespace>.svc.cluster.local, allowing clients to bypass the service proxy and resolve the direct IP address of a specific Pod. This mechanism is essential for stateful applications that require direct, addressable communication with individual cluster members.
- ✗
Use the Service name 'my-svc' which will round-robin between pods
Why it's wrong here
Querying the headless Service name directly returns the list of all backing Pod IP addresses via DNS A records, rather than a single stable virtual IP. Because there is no ClusterIP, kube-proxy does not configure load-balancing rules (such as iptables or IPVS) for this Service. Any round-robin behavior or connection distribution must be handled entirely on the client side by parsing the returned list of IPs.
- ✗
Use the Service's ClusterIP (None) to reach all pods
Why it's wrong here
Setting the clusterIP field to None explicitly instructs the Kubernetes control plane not to allocate a virtual IP address for the Service. Because no IP address is assigned to the Service itself, there is no network destination to target. Attempting to route traffic to a non-existent IP is impossible, meaning clients must rely on DNS resolution to discover the actual endpoints of the backing Pods.
- ✗
You cannot reach individual pods directly; you must use the Service name
Why it's wrong here
This assertion is incorrect because headless Services are specifically designed to facilitate direct, unproxied Pod-to-Pod communication. By bypassing the standard virtual IP, Kubernetes allows clients to discover individual Pod IPs directly through DNS. This enables stateful workloads, such as database clusters, to establish direct connections to specific master or replica nodes without an intermediate proxy.
Visual reference
Go deeper
Related to this question
Learn chapter
Installing Kubernetes with kubeadm
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
ClusterIP NodePort LoadBalancer
ClusterIP, NodePort, and LoadBalancer are three types of Kubernetes Services that control how traffic reaches your application pods inside the cluster or from outside.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.