Courseiva
Services and Networking →mediumMultiple Choice

CKA Services and Networking Practice Question

You run `kubectl port-forward service/my-svc 8080:80`. What does this command do?

⚠ Common exam trap

Candidates often mistakenly believe that `kubectl port-forward` routes traffic through the Service's ClusterIP. In reality, it resolves the Service's selector, picks a backing Pod, and establishes a direct tunnel to that Pod via the API server and the node's kubelet.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It forwards local port 8080 to port 80 on a Pod selected by the Service, bypassing the Service's ClusterIP.

The `kubectl port-forward` command forwards connections from a local port to a port on a Pod. When you specify a Service (e.g., `service/my-svc`), kubectl automatically selects an active Pod matching the Service's selector and forwards the traffic directly to that Pod. It completely bypasses the Service's ClusterIP and kube-proxy routing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    It forwards local port 8080 to port 80 on a Pod selected by the Service, bypassing the Service's ClusterIP.

    Why this is correct

    Port-forward resolves the Service to a backing Pod and tunnels local 8080 directly to that Pod's port 80, bypassing the ClusterIP entirely. This satisfies the scenario's constraint of reaching a Service-selected Pod without routing through the virtual IP.

  • ✗

    It forwards traffic from port 80 to port 8080 within the cluster.

    Why it's wrong here

    Port-forward binds a local port to a pod via the Service, so 8080 is the local listener and 80 the target port; traffic is not forwarded from 80 to 8080 inside the cluster. It is tempting because port mapping direction is easily reversed, and it would describe a reverse proxy or Service targetPort mapping.

  • ✗

    It creates a LoadBalancer Service on port 8080 forwarding to port 80.

    Why it's wrong here

    Port-forward does not create or modify any Service; it opens a transient local tunnel to an existing one. It is tempting because LoadBalancer Services also map ports, but that requires a Service manifest with type LoadBalancer and cloud provider integration, not a kubectl port-forward invocation.

  • ✗

    It exposes the Service on each node's port 8080.

    Why it's wrong here

    Port-forward creates a temporary tunnel from the local machine to a pod; it never binds a port on each node. NodePort Services do that. It is tempting because both expose an application on a port, but NodePort is a persistent cluster-wide Service type configured in YAML, not an ad hoc kubectl command.

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.