Courseiva
Services and Networking →easyMultiple Choice

CKAD Services and Networking Practice Question

A developer wants to access a specific pod's port 8080 from their local machine using a temporary connection. Which command should they use?

⚠ Common exam trap

Many exam-takers confuse `kubectl port-forward` with `kubectl proxy`, thinking both provide similar access, but `kubectl proxy` only proxies the API server and requires constructing URLs like `/api/v1/namespaces/default/pods/pod-name:8080/proxy/` to reach a pod, which is less direct and more error-prone.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl port-forward pod/pod-name 8080:8080

`kubectl port-forward` creates a temporary, direct tunnel from a local port to a port on a specific pod, allowing the developer to access the pod's port 8080 from their local machine without exposing the pod via a service. This command forwards local port 8080 to the pod's port 8080, enabling debugging or testing with tools like curl or a browser.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl exec -it pod-name -- sh

    Why it's wrong here

    kubectl exec -it pod-name -- sh opens an interactive shell session inside the pod's default container, letting you run commands from within that container. It does not create any tunnel or binding between your workstation and port 8080, so you still cannot reach the pod's port from your browser or client. It is a debugging and administration tool, not a network connectivity tool.

  • ✓

    kubectl port-forward pod/pod-name 8080:8080

    Why this is correct

    kubectl port-forward pod/pod-name 8080:8080 creates a local TCP listener on the specified host port (8080) and tunnels that traffic over the Kubernetes API server to port 8080 of the named pod. This makes the pod's application available at localhost:8080, which is exactly what the developer needs for direct access to a single pod. It is ephemeral and client-side; no Service or Ingress object is created, and the tunnel disappears when the command is terminated.

  • ✗

    kubectl proxy

    Why it's wrong here

    kubectl proxy starts an HTTP proxy server that exposes the Kubernetes API server on localhost, typically at 127.0.0.1:8001. It does not automatically forward arbitrary application ports; to reach the pod you would have to construct a special URL like /api/v1/namespaces/<namespace>/pods/<pod>/proxy/ and even then it only handles HTTP through the API's proxy feature. It grants access to the control plane API, not a direct TCP tunnel to port 8080.

  • ✗

    kubectl expose pod pod-name --port=8080

    Why it's wrong here

    kubectl expose pod pod-name --port=8080 creates a Service object that selects the pod and exposes port 8080 on the cluster's internal network (or via a LoadBalancer/NodePort if specified). It does not open a local port on your workstation, so you cannot simply browse to localhost:8080 afterwards. It also permanently persists as a Service and affects how the pod is reached by other cluster resources.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.