CKA Services and Networking Practice Question
You run `kubectl port-forward service/my-svc 8080:80`. What does this command do?
⚠ Common exam trap
Candidates often mistakenly believe that `kubectl port-forward` routes traffic through the Service's ClusterIP. In reality, it resolves the Service's selector, picks a backing Pod, and establishes a direct tunnel to that Pod via the API server and the node's kubelet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It forwards local port 8080 to port 80 on a Pod selected by the Service, bypassing the Service's ClusterIP.
The `kubectl port-forward` command forwards connections from a local port to a port on a Pod. When you specify a Service (e.g., `service/my-svc`), kubectl automatically selects an active Pod matching the Service's selector and forwards the traffic directly to that Pod. It completely bypasses the Service's ClusterIP and kube-proxy routing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It forwards local port 8080 to port 80 on a Pod selected by the Service, bypassing the Service's ClusterIP.
Why this is correct
Port-forward resolves the Service to a backing Pod and tunnels local 8080 directly to that Pod's port 80, bypassing the ClusterIP entirely. This satisfies the scenario's constraint of reaching a Service-selected Pod without routing through the virtual IP.
- ✗
It forwards traffic from port 80 to port 8080 within the cluster.
Why it's wrong here
Port-forward binds a local port to a pod via the Service, so 8080 is the local listener and 80 the target port; traffic is not forwarded from 80 to 8080 inside the cluster. It is tempting because port mapping direction is easily reversed, and it would describe a reverse proxy or Service targetPort mapping.
- ✗
It creates a LoadBalancer Service on port 8080 forwarding to port 80.
Why it's wrong here
Port-forward does not create or modify any Service; it opens a transient local tunnel to an existing one. It is tempting because LoadBalancer Services also map ports, but that requires a Service manifest with type LoadBalancer and cloud provider integration, not a kubectl port-forward invocation.
- ✗
It exposes the Service on each node's port 8080.
Why it's wrong here
Port-forward creates a temporary tunnel from the local machine to a pod; it never binds a port on each node. NodePort Services do that. It is tempting because both expose an application on a port, but NodePort is a persistent cluster-wide Service type configured in YAML, not an ad hoc kubectl command.
Go deeper
Related to this question
Key term
ClusterIP NodePort LoadBalancer
ClusterIP, NodePort, and LoadBalancer are three types of Kubernetes Services that control how traffic reaches your application pods inside the cluster or from outside.
Key term
kubectl Command Reference
kubectl is the command-line tool used to interact with and manage Kubernetes clusters by sending commands to the Kubernetes API.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.