CKAD Services and Networking Practice Question
A Service of type NodePort is created with 'spec.ports[0].nodePort: 30080'. The cluster nodes have IPs 10.0.0.1, 10.0.0.2. Which command can be used to test connectivity to the Service from outside the cluster?
⚠ Common exam trap
A common mix-up: candidates confuse the clusterIP port (80) with the nodePort (30080), or assume that the clusterIP (e.g., 10.96.0.1) is reachable from outside the cluster, when in fact it is only routable within the cluster network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
curl 10.0.0.1:30080
A NodePort service exposes the same port (nodePort: 30080) on every cluster node's IP address. From outside the cluster, you can reach the service by targeting any node's IP and the nodePort, so `curl 10.0.0.1:30080` will connect to the service via node 10.0.0.1.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
curl 10.0.0.1:30080
Why this is correct
This is correct because NodePort services are published on the port specified in `spec.ports[0].nodePort` (30080) on every node's IP address. Since 10.0.0.1 is a node IP, traffic sent to that address on port 30080 is intercepted by kube-proxy and forwarded to the backing pods, regardless of which node actually runs the pod.
- ✗
curl 10.0.0.1:80 --header 'Host: service.namespace.svc.cluster.local'
Why it's wrong here
This is incorrect because the `Host` header is only used by Ingress controllers to route virtual hosts, not by NodePort services. NodePort routing is solely based on the destination IP:port; the host header is ignored. Additionally, port 80 is the service port, not the nodePort 30080, so the request would not even match the NodePort listener, and the service's cluster-local hostname is only resolvable inside the cluster, not from a node IP.
- ✗
curl 10.0.0.1:80
Why it's wrong here
This is incorrect because port 80 on a node IP is not the NodePort. In a NodePort service, the port in `spec.ports[0].port` (80) is the ClusterIP port, which is only reachable from inside the cluster via the ClusterIP. The NodePort is a separate high-port (30080) bound to all node interfaces; sending to port 80 on a node IP will not hit any load balancer or NodePort rule.
- ✗
curl 10.96.0.1:30080
Why it's wrong here
This is incorrect because 10.96.0.1 is a cluster IP address, not a node IP, and NodePort services are explicitly exposed only on each node's IP (e.g., 10.0.0.1). The nodePort (30080) is not bound to the ClusterIP; the ClusterIP only serves on its own port (80). From outside the cluster, 10.96.0.1 is not routable, and even if it were, the nodePort is not defined there.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.