CKAD Services and Networking Practice Question
A developer needs to expose a deployment named 'web-app' running in the 'default' namespace on port 8080 internally within the cluster. Which kubectl command creates a ClusterIP service that selects pods with label 'app: web'?
⚠ Common exam trap
Test-takers frequently assume `kubectl expose` automatically uses the deployment's labels as the service selector, but the `--selector` flag is required when the target pod label differs from the deployment's selector, and `kubectl create service clusterip` lacks a `--selector` flag entirely, leading to a service with no endpoints.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl expose deployment web-app --port=8080 --target-port=8080 --selector=app=web
`kubectl expose deployment web-app --port=8080 --target-port=8080 --selector=app=web` creates a ClusterIP service by default (no `--type` flag defaults to ClusterIP), and the `--selector` flag explicitly sets the label selector to `app=web`, ensuring the service routes traffic to pods with that label. The `--port` flag defines the service port, and `--target-port` defines the container port (8080), matching the requirement for internal cluster exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
kubectl expose deployment web-app --port=8080 --target-port=8080 --selector=app=web
Why this is correct
This command correctly creates a Service from the existing Deployment named web-app. The --selector=app=web flag ensures the Service's label selector matches the pods that belong to the Deployment, so traffic is routed only to those pod replicas. Port 8080 is set as the Service port (the port clients connect to) and --target-port=8080 forwards traffic to the same port on the selected pods, which is appropriate if the container listens on 8080. Because kubectl expose defaults to ClusterIP, this yields an internal stable IP for intra-cluster communication.
- ✗
kubectl expose deployment web-app --port=8080 --target-port=8080 --type=ClusterIP
Why it's wrong here
This command omits the --selector flag, so kubectl expose will automatically copy the Deployment's own label selector into the Service. If the Deployment's selector is not app=web, the Service will target the wrong pods or none at all, failing to reach the intended backend. Additionally, specifying --type=ClusterIP is redundant because that is already the default Service type, so it adds no value here. The explicit --selector=app=web is required to guarantee the Service correctly maps to the Deployment's pods.
- ✗
kubectl run web-app --image=nginx --port=8080 --expose
Why it's wrong here
This command does not expose the existing Deployment; instead, it creates a brand-new Deployment (or Pod, depending on kubectl version) named web-app with the nginx image and then creates a Service to expose that new workload. The target-port 8080 is set on the new container, but this has no connection to the existing Deployment's pods or their labels. Since the goal is to create a Service for the already-running Deployment, this command would create duplicate resources and likely cause confusion or conflicts rather than exposing the intended workload.
- ✗
kubectl create service clusterip web-app --tcp=8080:8080 --selector=app=web
Why it's wrong here
The kubectl create service clusterip command cannot accept a --selector flag; this flag is simply not supported by that subcommand, so the command will fail with an error. Even if it did accept the flag, this approach creates a Service in isolation without linking it to the Deployment object, meaning the Service's selector must be manually maintained and there is no automatic synchronization of endpoints. The kubectl expose command is the proper way to generate a Service from an existing resource because it derives the selector and port configuration from the Deployment's spec.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.