CKAD Services and Networking Practice Question
A user runs 'kubectl get endpoints my-service' and sees no endpoints listed. The service has a selector 'app: my-app'. Pods with that label exist and are running. What is the most likely cause?
⚠ Common exam trap
The trap is that 'running' does not equal 'ready'. A pod must be both selected and ready to appear in Endpoints. Readiness probes determine readiness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The pods are not ready (readiness probe failing)
In Kubernetes, a Service creates Endpoints only for pods that match its selector and are ready. Because the pods are labeled app: my-app and match the selector, the missing endpoints indicate the pods are not passing their readiness probes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The service selector does not match the pod labels
Why it's wrong here
The Endpoints controller continuously watches for pods whose labels exactly match the service's spec.selector. If no running pod carries that label set, the controller creates an Endpoints object with an empty subsets list, resulting in no addresses. This is the most frequent cause of an empty endpoints output and should be the first thing you verify by inspecting pod labels with 'kubectl get pods --show-labels'.
- ✗
The pods are not assigned an IP address
Why it's wrong here
In a healthy cluster, every pod that reaches the Running state is assigned an IP address by the CNI plugin (e.g., Calico or Flannel). If a pod has no IP, it would remain in a Pending or ContainerCreating state, not Running, and thus would not be eligible for endpoints regardless of selector matching. The absence of endpoints is therefore not explained by missing IP assignments; the pods would simply not be counted at all.
- ✗
The service name is incorrect
Why it's wrong here
If you ran 'kubectl get endpoints my service' and the service name were incorrect, kubectl would return an error like 'Error from server (NotFound): endpoints "my service" not found', not an empty result. The command successfully returned an Endpoints object, which means the service exists and the name is correct. An empty subsets list indicates the object was found, so a wrong name cannot be the reason for seeing no endpoints.
- ✓
The pods are not ready (readiness probe failing)
Why this is correct
Even if readiness probe fails, the endpoints would still exist if the selector matches; the pod would be removed from endpoints only if it fails readiness, but initially endpoints would have been populated. If no endpoints at all, selector mismatch is the first thing to check.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.