CKAD Services and Networking Practice Question
A ClusterIP service named 'svc' has no endpoints. Which command can you use to debug why the service is not routing traffic?
⚠ Common exam trap
Test-takers frequently assume `kubectl describe service` is sufficient to debug endpoint issues, but it only shows the selector, not the actual endpoints, so you must explicitly check the endpoints object to confirm the routing target is missing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl get endpoints svc
`kubectl get endpoints svc` directly shows the list of pod IPs and ports that the ClusterIP service is routing traffic to. If the service has no endpoints, this command will return an empty list, confirming that no pods match the service's selector, which is the most common reason for traffic not being routed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
kubectl get endpoints svc
Why this is correct
This command directly queries the Endpoints API object that shares the Service's name, displaying the backend pod IPs and ports that the ClusterIP Service routes to. When the selector no longer matches any pods, the output shows `<none>` for the endpoints list, confirming there is no backing set of pods. It is the canonical way to verify the existence (or absence) of endpoints for a Service.
- ✗
kubectl describe service svc
Why it's wrong here
This command produces a human-readable summary of the Service object itself, including its Type, ClusterIP, Ports, Selector, and a computed `Endpoints` line. However, that line is merely derived from the separate Endpoints resource and does not let you inspect the Endpoints object's full details or diagnose why it is empty; you would still need to query the Endpoints resource directly. It provides useful context but is not the authoritative check for the missing endpoints.
- ✗
kubectl logs svc
Why it's wrong here
A Service is a virtual networking abstraction represented by a ClusterIP and kube-proxy rules, not a runnable process or a pod. The `kubectl logs` command retrieves stdout/stderr from a container in a specific pod, so a service name is an invalid target because a Service has no containers to produce logs. This command fails with an error rather than helping you determine that the endpoints list is empty.
- ✗
kubectl exec -it svc -- /bin/sh
Why it's wrong here
`kubectl exec` requires a target that contains a running container, such as a pod, because it attaches to an existing process tree or starts a process inside that container. A Service is not a workload; it has no container filesystem, no process tree, and no runtime in which a shell could execute. Passing a Service name as the target fails because Kubernetes has nothing to attach or exec into; inspecting the Endpoints resource is the proper way to see the Service's backing pods.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.