CKA Services and Networking Practice Question
You want to temporarily access a pod's HTTP endpoint on port 8080 from your local machine on port 9090. Which command should you use?
⚠ Common exam trap
Watch out — candidates often confuse `kubectl port-forward` with `kubectl expose` or `kubectl proxy`, mistakenly thinking those commands provide direct local access to a pod's port, when in fact `kubectl expose` creates a Service (requiring additional access methods) and `kubectl proxy` targets the API server, not the pod.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl port-forward pod/my-pod 9090:8080
`kubectl port-forward` creates a direct tunnel from a local port (9090) to a pod's port (8080) over the Kubernetes API server, enabling temporary access to a pod's HTTP endpoint without exposing a service. This is the standard method for debugging or testing a pod's network endpoint from a local machine.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl exec -it my-pod -- /bin/bash
Why it's wrong here
This command starts an interactive bash session inside the container of the specified pod. While useful for troubleshooting and inspecting the container's filesystem directly, it does not establish a network tunnel or map any ports to your local machine to allow direct HTTP traffic access.
- ✗
kubectl proxy --port=9090
Why it's wrong here
This command creates a local proxy server that allows secure communication with the Kubernetes API server on port 9090. It is designed for querying cluster resources and API endpoints using your local credentials, rather than routing traffic directly to an individual pod's application port.
- ✗
kubectl expose pod my-pod --port=9090 --target-port=8080
Why it's wrong here
This command creates a persistent Kubernetes Service object to expose the pod within the cluster network. While it maps port 9090 to target port 8080, it is a permanent configuration change rather than a temporary, direct connection from your local workstation.
- ✓
kubectl port-forward pod/my-pod 9090:8080
Why this is correct
This command establishes a secure, temporary tunnel that forwards traffic from port 9090 on your local machine directly to port 8080 of the specified pod. It is the ideal tool for debugging and temporarily accessing a pod's web endpoint without exposing it to the public internet or creating permanent cluster resources.
Go deeper
Related to this question
Learn chapter
Installing Kubernetes with kubeadm
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
kubectl Command Reference
kubectl is the command-line tool used to interact with and manage Kubernetes clusters by sending commands to the Kubernetes API.
About these practice questions
Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.