Courseiva
Services and Networking →hardMultiple Choice

CKAD Services and Networking Practice Question

A ClusterIP service named 'svc' has no endpoints. Which command can you use to debug why the service is not routing traffic?

⚠ Common exam trap

Test-takers frequently assume `kubectl describe service` is sufficient to debug endpoint issues, but it only shows the selector, not the actual endpoints, so you must explicitly check the endpoints object to confirm the routing target is missing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl get endpoints svc

`kubectl get endpoints svc` directly shows the list of pod IPs and ports that the ClusterIP service is routing traffic to. If the service has no endpoints, this command will return an empty list, confirming that no pods match the service's selector, which is the most common reason for traffic not being routed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    kubectl get endpoints svc

    Why this is correct

    This command directly queries the Endpoints API object that shares the Service's name, displaying the backend pod IPs and ports that the ClusterIP Service routes to. When the selector no longer matches any pods, the output shows `<none>` for the endpoints list, confirming there is no backing set of pods. It is the canonical way to verify the existence (or absence) of endpoints for a Service.

  • ✗

    kubectl describe service svc

    Why it's wrong here

    This command produces a human-readable summary of the Service object itself, including its Type, ClusterIP, Ports, Selector, and a computed `Endpoints` line. However, that line is merely derived from the separate Endpoints resource and does not let you inspect the Endpoints object's full details or diagnose why it is empty; you would still need to query the Endpoints resource directly. It provides useful context but is not the authoritative check for the missing endpoints.

  • ✗

    kubectl logs svc

    Why it's wrong here

    A Service is a virtual networking abstraction represented by a ClusterIP and kube-proxy rules, not a runnable process or a pod. The `kubectl logs` command retrieves stdout/stderr from a container in a specific pod, so a service name is an invalid target because a Service has no containers to produce logs. This command fails with an error rather than helping you determine that the endpoints list is empty.

  • ✗

    kubectl exec -it svc -- /bin/sh

    Why it's wrong here

    `kubectl exec` requires a target that contains a running container, such as a pod, because it attaches to an existing process tree or starts a process inside that container. A Service is not a workload; it has no container filesystem, no process tree, and no runtime in which a shell could execute. Passing a Service name as the target fails because Kubernetes has nothing to attach or exec into; inspecting the Endpoints resource is the proper way to see the Service's backing pods.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.