CKAD Application Deployment Practice Question
A team is deploying a microservice that must be reachable within the cluster via a stable DNS name. They also need to distribute traffic among pods. Which Kubernetes resource provides both service discovery and load balancing?
⚠ Common exam trap
It's easy for candidates to confuse Ingress with internal service discovery, but Ingress is designed for external traffic routing and does not provide a stable DNS name for pod-to-pod communication within the cluster.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Service
A Service in Kubernetes provides a stable DNS name (via cluster DNS, e.g., CoreDNS) that resolves to the Service's ClusterIP, and it load-balances traffic across the pods selected by its label selector using iptables or IPVS rules. This directly fulfills the requirement for both service discovery and load balancing within the cluster.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Service
Why this is correct
A Service provides a stable virtual IP (ClusterIP) and a DNS record via the cluster's internal DNS (e.g., <service>.<namespace>.svc.cluster.local), so clients can resolve the backend without knowing individual Pod IPs. It uses label selectors to identify target Pods and load-balances traffic across them, which is precisely what this microservice needs for reliable internal reachability. This is the standard Kubernetes abstraction for service discovery within a cluster.
- ✗
ConfigMap
Why it's wrong here
A ConfigMap is an API object for storing non-confidential key-value configuration data, such as environment variables, command-line arguments, or config file contents. It has no IP address, DNS name, or endpoint mechanism, and mounting it into a Pod does not make the Pod reachable to other components. Thus, while a ConfigMap might hold the microservice's settings, it cannot provide the network endpoint that the deployment requires.
- ✗
Secret
Why it's wrong here
A Secret is designed to hold sensitive information (e.g., passwords, tokens, keys) and is encoded in etcd; it is injected into Pods via volume mounts or environment variables. A Secret does not create any networking objects or assign any cluster-internal identity, so it cannot be used for service discovery or stable network addressing. Even though a Secret might contain connection details for another service, it does not itself make the microservice reachable.
- ✗
Ingress
Why it's wrong here
An Ingress is an L7 (HTTP/HTTPS) routing object that manages external access to Services, typically via path- or host-based rules through a controller (e.g., NGINX). It exposes web traffic from outside the cluster, but it does not create an internal stable IP/DNS entry for Pod-to-Pod communication within the cluster. Service discovery inside Kubernetes relies on the built-in Service object and DNS, not on Ingress.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.