CKA Services and Networking Practice Question
You have an Ingress resource with a TLS section specifying a secret named 'tls-secret'. The certificate in 'tls-secret' is expired. What happens when a client connects via HTTPS to the Ingress host?
⚠ Common exam trap
It's easy for candidates to assume the Ingress controller validates certificate expiration and would refuse the connection, but in reality, TLS certificate expiration is only enforced by the client, not the server.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TLS handshake succeeds but the client receives a warning about the expired certificate
When a client connects via HTTPS to an Ingress host with an expired TLS certificate, the Ingress controller (e.g., NGINX) still terminates the TLS handshake successfully because TLS termination does not validate certificate expiration at the server side. The expired certificate is presented to the client, and the client's browser or tool (e.g., curl) will show a warning about the expired certificate but the connection proceeds unless the client is configured to reject expired certificates. The Ingress controller does not enforce certificate validity; it only serves the configured secret.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
TLS handshake succeeds but the client receives a warning about the expired certificate
Why this is correct
When an Ingress controller loads a TLS secret, it does not validate the expiration date of the certificate during the configuration phase. It will successfully bind the certificate to the listener and complete the TLS handshake with clients. However, because the certificate's validity period has passed, the client's browser or TLS library will flag it as untrusted and display an expiration warning.
- ✗
The Ingress controller returns an error and refuses to terminate TLS
Why it's wrong here
Ingress controllers, such as ingress-nginx, act as reverse proxies and do not perform runtime validation checks on the expiration dates of certificates loaded from Kubernetes Secrets. They will happily load and serve any syntactically valid PEM-formatted certificate-key pair. Consequently, the controller will not throw a configuration error or refuse to terminate the TLS connection.
- ✗
The Ingress controller automatically renews the certificate
Why it's wrong here
Standard Kubernetes Ingress controllers do not possess native capabilities to automatically renew expired certificates or interact with certificate authorities like Let's Encrypt. To achieve automated certificate lifecycle management, you must deploy an external operator such as cert-manager. Without such an add-on, the expired certificate remains in the Secret indefinitely until manually updated.
- ✗
The secret is ignored and HTTP is used instead
Why it's wrong here
The Ingress controller respects the declarative state of the Ingress resource and will not silently ignore the TLS configuration block due to an expired certificate. It continues to serve the configured domain over HTTPS using the provided secret. The controller will never automatically downgrade the connection to unencrypted HTTP, as doing so would violate the security intent defined in the manifest.
Go deeper
Related to this question
Key term
Ingress Controller
An Ingress Controller is a specialized component that manages external access to services in a Kubernetes cluster by processing Ingress resources and routing traffic according to defined rules.
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.