CKAD Services and Networking Practice Question
A developer wants to expose a Deployment named 'web-app' (with label 'app: web') as a ClusterIP service on port 80. Which command achieves this?
⚠ Common exam trap
Many candidates confuse `kubectl expose` with `kubectl create service`; `expose` automatically derives selectors from the resource (Deployment, Pod, etc.), while `create service` creates a bare Service without selectors unless explicitly provided.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl expose deployment web-app --port=80
`kubectl expose deployment web-app --port=80` creates a ClusterIP Service that selects Pods based on the labels of the specified Deployment (in this case, `app: web`). The `expose` command automatically reads the Pod template labels from the Deployment and applies them as the Service's selector, then maps the Service's port 80 to the target port of the containers in the selected Pods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl expose service web-app --port=80
Why it's wrong here
kubectl expose service web-app --port=80 targets a Service object as the source, but Services are not exposed as new Services in this way; the expose command expects a controller resource like a deployment, replica set, or pod to generate a Service that selects its pods. Running this against a Service would either fail or create a Service that selects no pods, leaving endpoints empty and traffic unable to reach the application.
- ✗
kubectl create service clusterip web-app --tcp=80
Why it's wrong here
kubectl create service clusterip web-app --tcp=80 creates a ClusterIP Service resource directly, but it does not automatically attach a selector to the Deployment's pods. Without the selector (e.g., app=web-app) and target port matching the container's port, the Service has no endpoints, so it cannot route traffic to the deployment's pods; this requires manually editing the Service to add the correct selector, whereas kubectl expose deployment does this automatically.
- ✓
kubectl expose deployment web-app --port=80
Why this is correct
kubectl expose deployment web-app --port=80 is the correct imperative command because it creates a Service from the Deployment resource, automatically inheriting the Deployment's pod selector and setting the Service's target port to the container port. This ensures the Service has endpoints that match the pods managed by the Deployment, providing a stable DNS name and load-balanced access to the application.
- ✗
kubectl expose pod web-app --port=80
Why it's wrong here
kubectl expose pod web-app --port=80 creates a Service that selects a single pod directly, which is not scalable because the Service's endpoints are tied to that exact pod. If the pod is deleted or recreated (e.g., during a rolling update or scale-down), the Service's selector becomes stale and traffic fails; a Deployment-backed Service ensures endpoints track the dynamically managed pods.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.