Courseiva
Services and Networking →hardMultiple Choice

CKAD Services and Networking Practice Question

An Ingress has two rules: - host: app.example.com, path: /api -> service-a:80 - host: api.example.com, path: / -> service-b:80 A request to `app.example.com/api/v1` reaches which service?

⚠ Common exam trap

Test-takers frequently assume path matching requires an exact match (e.g., `/api` only matches `/api`, not `/api/v1`), but Kubernetes Ingress uses prefix matching by default, so `/api` matches any path starting with `/api`.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

service-a

Ingress rules match the longest prefix of the request path for the given host. For `app.example.com/api/v1`, the path `/api` is a prefix match (since `/api/v1` starts with `/api`), so it routes to service-a:80. The second rule requires host `api.example.com`, which does not match, so service-b is not considered.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Both services

    Why it's wrong here

    Both services is wrong because a single HTTP request can be routed to only one backend, and these two rules do not both apply to the same request. The request uses Host: app.example.com and path /api/v1, which satisfies the app.example.com/api rule but not the api.example.com rule, so service-b is never contacted. Only one rule matches, therefore only one Service receives traffic.

  • ✗

    Neither service

    Why it's wrong here

    Neither service is incorrect: although a host mismatch might appear to block everything, the request's Host is app.example.com and the path /api/v1 starts with the configured path /api. The prefix match for path /api is valid, and because the host also matches the rule targeting service-a, the request is routed successfully. Thus it is not true that no Service matches.

  • ✓

    service-a

    Why this is correct

    service-a is correct: the ingress rule for host app.example.com with path /api uses Prefix path matching, and the request URL /api/v1 begins with /api, so the path condition is satisfied. Since the Host header also matches app.example.com, the controller forwards the request to service-a. No other rule has both matching host and path.

  • ✗

    service-b

    Why it's wrong here

    service-b cannot receive this request because the rule associated with it is for the host api.example.com, while this request has Host: app.example.com. In Kubernetes Ingress, host matching is required before the path is considered, so even if the path component appeared to overlap, the Host header mismatch disqualifies the rule. Therefore service-b is not selected.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.