Courseiva
Services and Networking →hardMultiple Choice

CKA Services and Networking Practice Question

You have an Ingress resource with a TLS section specifying a secret named 'tls-secret'. The certificate in 'tls-secret' is expired. What happens when a client connects via HTTPS to the Ingress host?

⚠ Common exam trap

It's easy for candidates to assume the Ingress controller validates certificate expiration and would refuse the connection, but in reality, TLS certificate expiration is only enforced by the client, not the server.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TLS handshake succeeds but the client receives a warning about the expired certificate

When a client connects via HTTPS to an Ingress host with an expired TLS certificate, the Ingress controller (e.g., NGINX) still terminates the TLS handshake successfully because TLS termination does not validate certificate expiration at the server side. The expired certificate is presented to the client, and the client's browser or tool (e.g., curl) will show a warning about the expired certificate but the connection proceeds unless the client is configured to reject expired certificates. The Ingress controller does not enforce certificate validity; it only serves the configured secret.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    TLS handshake succeeds but the client receives a warning about the expired certificate

    Why this is correct

    When an Ingress controller loads a TLS secret, it does not validate the expiration date of the certificate during the configuration phase. It will successfully bind the certificate to the listener and complete the TLS handshake with clients. However, because the certificate's validity period has passed, the client's browser or TLS library will flag it as untrusted and display an expiration warning.

  • ✗

    The Ingress controller returns an error and refuses to terminate TLS

    Why it's wrong here

    Ingress controllers, such as ingress-nginx, act as reverse proxies and do not perform runtime validation checks on the expiration dates of certificates loaded from Kubernetes Secrets. They will happily load and serve any syntactically valid PEM-formatted certificate-key pair. Consequently, the controller will not throw a configuration error or refuse to terminate the TLS connection.

  • ✗

    The Ingress controller automatically renews the certificate

    Why it's wrong here

    Standard Kubernetes Ingress controllers do not possess native capabilities to automatically renew expired certificates or interact with certificate authorities like Let's Encrypt. To achieve automated certificate lifecycle management, you must deploy an external operator such as cert-manager. Without such an add-on, the expired certificate remains in the Secret indefinitely until manually updated.

  • ✗

    The secret is ignored and HTTP is used instead

    Why it's wrong here

    The Ingress controller respects the declarative state of the Ingress resource and will not silently ignore the TLS configuration block due to an expired certificate. It continues to serve the configured domain over HTTPS using the provided secret. The controller will never automatically downgrade the connection to unencrypted HTTP, as doing so would violate the security intent defined in the manifest.

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.