CKAD Services and Networking Practice Question
An Ingress has two rules: - host: app.example.com, path: /api -> service-a:80 - host: api.example.com, path: / -> service-b:80 A request to `app.example.com/api/v1` reaches which service?
⚠ Common exam trap
Test-takers frequently assume path matching requires an exact match (e.g., `/api` only matches `/api`, not `/api/v1`), but Kubernetes Ingress uses prefix matching by default, so `/api` matches any path starting with `/api`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
service-a
Ingress rules match the longest prefix of the request path for the given host. For `app.example.com/api/v1`, the path `/api` is a prefix match (since `/api/v1` starts with `/api`), so it routes to service-a:80. The second rule requires host `api.example.com`, which does not match, so service-b is not considered.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Both services
Why it's wrong here
Both services is wrong because a single HTTP request can be routed to only one backend, and these two rules do not both apply to the same request. The request uses Host: app.example.com and path /api/v1, which satisfies the app.example.com/api rule but not the api.example.com rule, so service-b is never contacted. Only one rule matches, therefore only one Service receives traffic.
- ✗
Neither service
Why it's wrong here
Neither service is incorrect: although a host mismatch might appear to block everything, the request's Host is app.example.com and the path /api/v1 starts with the configured path /api. The prefix match for path /api is valid, and because the host also matches the rule targeting service-a, the request is routed successfully. Thus it is not true that no Service matches.
- ✓
service-a
Why this is correct
service-a is correct: the ingress rule for host app.example.com with path /api uses Prefix path matching, and the request URL /api/v1 begins with /api, so the path condition is satisfied. Since the Host header also matches app.example.com, the controller forwards the request to service-a. No other rule has both matching host and path.
- ✗
service-b
Why it's wrong here
service-b cannot receive this request because the rule associated with it is for the host api.example.com, while this request has Host: app.example.com. In Kubernetes Ingress, host matching is required before the path is considered, so even if the path component appeared to overlap, the Host header mismatch disqualifies the rule. Therefore service-b is not selected.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.