Courseiva
Services and Networking →easyMultiple Choice

CKA Services and Networking Practice Question

You need to temporarily access a pod's HTTP endpoint on port 8080 from your local machine on port 8080. Which kubectl command should you use?

⚠ Common exam trap

Many candidates confuse `kubectl port-forward` with `kubectl expose` or `kubectl proxy`, thinking those commands provide direct pod access, when in fact `port-forward` is the only command that creates a direct, temporary tunnel from a local port to a specific pod's port without creating a Service or proxying through the API server.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl port-forward pod/my-pod 8080:8080

`kubectl port-forward` creates a direct tunnel from a local port to a specific pod, allowing you to access the pod's HTTP endpoint on port 8080 from your local machine on port 8080. This command targets the pod directly (`pod/my-pod`) and maps local port 8080 to the pod's port 8080, which is exactly what the question requires for temporary, ad-hoc access without creating a Service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl expose pod my-pod --port=8080

    Why it's wrong here

    This command attempts to create a new Service resource exposing the specified pod, which is a permanent cluster-level change rather than a temporary local access mechanism. It does not establish a direct tunnel from your local machine to the pod's port, making it unsuitable for quick, temporary debugging.

  • ✗

    kubectl proxy --port=8080

    Why it's wrong here

    This command runs a local proxy server to access the Kubernetes API server securely from your localhost. While it allows you to query API endpoints and access services via the API proxy path, it does not establish a direct TCP port-forwarding tunnel to a specific application pod's port.

  • ✗

    kubectl port-forward service/my-service 8080:8080

    Why it's wrong here

    This command sets up port forwarding to a Service resource rather than directly targeting a specific pod. While it eventually routes traffic to an underlying pod selected by the service, it fails to meet the requirement of directly and temporarily targeting a specific pod instance.

  • ✓

    kubectl port-forward pod/my-pod 8080:8080

    Why this is correct

    This command successfully establishes a secure, temporary tunnel from your local machine's port 8080 directly to port 8080 of the specified pod. It is the standard, lightweight method for debugging and interacting with a pod's endpoint without exposing it to the wider network.

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.