CKAD Application Design and Build Practice Question
A developer needs to expose a deployment named 'web-app' running on port 8080 to external traffic. The cluster is on-premises with no cloud load balancer. Which service type should be used?
⚠ Common exam trap
Candidates often choose LoadBalancer (C) by default when they see 'expose to external traffic,' forgetting that LoadBalancer requires a cloud provider's external LB, which is not available in on-premises clusters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NodePort
(NodePort) is correct because it exposes a service on a static port on each node's IP address, allowing external traffic to reach the 'web-app' deployment on port 8080 without requiring a cloud load balancer. In on-premises clusters, NodePort is the standard service type for external access when no cloud LB is available, as it opens a high-port (30000-32767) on every node that forwards traffic to the ClusterIP service.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ExternalName
Why it's wrong here
ExternalName maps a service to a DNS name (like an alias) by returning a CNAME record, with no selectors and no defined ports. It doesn't route traffic to pods or provide any port mapping, so a Deployment's pod IPs and container ports can never be reached through it. Therefore it cannot expose the 'web app' workload to clients, making it an invalid choice for this scenario.
- ✗
ClusterIP
Why it's wrong here
ClusterIP is the default Service type that assigns a stable virtual IP from the cluster's internal pool, load-balancing traffic to pod endpoints only within the cluster network. It is inaccessible from outside the cluster unless you add a NodePort, LoadBalancer, ingress controller, or port-forward, none of which are present. Thus a ClusterIP Service alone cannot provide external access to the web app, even though it is useful for internal communication.
- ✗
LoadBalancer
Why it's wrong here
LoadBalancer extends NodePort by requesting an external load balancer from the cloud provider (e.g., AWS ELB, GCP LB) via the service's 'type' field. On-premises or bare-metal clusters without a cloud controller manager cannot provision an external LB, and the service often remains in 'Pending' or merely falls back to NodePort behavior without actually creating a routable LB. Since the developer needs a reliable way to expose the deployment externally in a generic environment, LoadBalancer is only appropriate when a cloud provider integration is guaranteed, making it wrong in this unspecified context.
- ✓
NodePort
Why this is correct
NodePort is the simplest Service type that exposes an application to traffic from outside the cluster by opening a static port (default range 30000-32767) on every worker node's IP address. Traffic sent to any node's IP at that port is forwarded through the Service to the backing pod(s) selected by the Deployment, regardless of which node actually runs those pods. In the absence of a cloud-provider load balancer, NodePort works on any Kubernetes cluster and is precisely the mechanism that satisfies the developer's requirement to expose the web app externally.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.