Courseiva
Workloads & Scheduling →mediumMultiple Choice

CKA Workloads & Scheduling Practice Question

Your team is deploying a new application that consists of a web frontend and a backend API. The frontend must be accessible from outside the cluster, and the backend should only be accessible from within the cluster. The cluster has multiple namespaces: 'frontend' and 'backend'. You have been asked to design the deployment. The frontend Deployment should have 5 replicas, and the backend Deployment should have 3 replicas. Additionally, you need to ensure that the frontend pods can communicate with the backend pods using a stable DNS name. You also want to isolate the backend from other namespaces. Which set of resources should you create?

⚠ Common exam trap

The trap here is that candidates often forget that a ClusterIP Service cannot be accessed from outside the cluster, and they may incorrectly choose a LoadBalancer or NodePort for the backend, or omit the NetworkPolicy needed to enforce isolation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Frontend: Deployment, Service (LoadBalancer); Backend: Deployment, Service (ClusterIP); NetworkPolicy to allow ingress from frontend namespace and deny others

It uses a LoadBalancer Service for the frontend to provide external access, a ClusterIP Service for the backend to restrict access to within the cluster, and a NetworkPolicy that allows ingress traffic from the frontend namespace to the backend while denying all other ingress, thus isolating the backend. This ensures the frontend pods can reach the backend via a stable DNS name (the ClusterIP Service's DNS name) and meets the requirement of backend isolation from other namespaces.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Frontend: Deployment, Service (NodePort); Backend: Deployment, Service (ClusterIP); no NetworkPolicy

    Why it's wrong here

    While using a NodePort Service exposes the frontend on a static port across each node, this configuration completely lacks a NetworkPolicy to secure the backend. Without a NetworkPolicy, the backend ClusterIP Service remains open to unauthorized traffic from any pod within the Kubernetes cluster, failing to meet basic isolation requirements.

  • ✗

    Frontend: Deployment, Service (ClusterIP); Backend: Deployment, Service (ClusterIP); NetworkPolicy to allow ingress from frontend namespace

    Why it's wrong here

    Exposing the frontend via a ClusterIP Service restricts its accessibility solely to clients inside the cluster. Because the frontend application requires external access to serve public users, this configuration fails because ClusterIP does not provision an external IP address or route external traffic.

  • ✗

    Frontend: Deployment, Service (LoadBalancer); Backend: Deployment, Service (LoadBalancer); NetworkPolicy to allow only frontend to backend

    Why it's wrong here

    Utilizing a LoadBalancer Service for the backend is a severe security misconfiguration because it provisions a public-facing cloud load balancer, exposing the database or API directly to the internet. The backend should only be reachable internally via a ClusterIP, making this architecture unnecessarily vulnerable and costly.

  • ✓

    Frontend: Deployment, Service (LoadBalancer); Backend: Deployment, Service (ClusterIP); NetworkPolicy to allow ingress from frontend namespace and deny others

    Why this is correct

    This architecture correctly leverages a LoadBalancer Service to route external public traffic to the frontend deployment, while keeping the backend isolated using an internal-only ClusterIP Service. Additionally, the NetworkPolicy enforces strict zero-trust security by explicitly allowing ingress traffic only from the frontend namespace while dropping all other non-compliant cluster traffic.

About these practice questions

Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.