Courseiva
Services and Networking →easyMultiple Choice

CKA Services and Networking Practice Question

You want to temporarily access a pod's HTTP endpoint on port 8080 from your local machine on port 9090. Which command should you use?

⚠ Common exam trap

Watch out — candidates often confuse `kubectl port-forward` with `kubectl expose` or `kubectl proxy`, mistakenly thinking those commands provide direct local access to a pod's port, when in fact `kubectl expose` creates a Service (requiring additional access methods) and `kubectl proxy` targets the API server, not the pod.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl port-forward pod/my-pod 9090:8080

`kubectl port-forward` creates a direct tunnel from a local port (9090) to a pod's port (8080) over the Kubernetes API server, enabling temporary access to a pod's HTTP endpoint without exposing a service. This is the standard method for debugging or testing a pod's network endpoint from a local machine.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl exec -it my-pod -- /bin/bash

    Why it's wrong here

    This command starts an interactive bash session inside the container of the specified pod. While useful for troubleshooting and inspecting the container's filesystem directly, it does not establish a network tunnel or map any ports to your local machine to allow direct HTTP traffic access.

  • ✗

    kubectl proxy --port=9090

    Why it's wrong here

    This command creates a local proxy server that allows secure communication with the Kubernetes API server on port 9090. It is designed for querying cluster resources and API endpoints using your local credentials, rather than routing traffic directly to an individual pod's application port.

  • ✗

    kubectl expose pod my-pod --port=9090 --target-port=8080

    Why it's wrong here

    This command creates a persistent Kubernetes Service object to expose the pod within the cluster network. While it maps port 9090 to target port 8080, it is a permanent configuration change rather than a temporary, direct connection from your local workstation.

  • ✓

    kubectl port-forward pod/my-pod 9090:8080

    Why this is correct

    This command establishes a secure, temporary tunnel that forwards traffic from port 9090 on your local machine directly to port 8080 of the specified pod. It is the ideal tool for debugging and temporarily accessing a pod's web endpoint without exposing it to the public internet or creating permanent cluster resources.

About these practice questions

Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.