Courseiva
Services and Networking →mediumMultiple Choice

CKAD Services and Networking Practice Question

An Ingress is configured for host-based routing with two hosts: 'app1.example.com' and 'app2.example.com'. A request to 'app1.example.com' should go to service 'svc1'. Which field in the Ingress spec specifies the host?

⚠ Common exam trap

Many candidates confuse `spec.rules.host` with `spec.tls.hosts` or incorrectly assume the host is nested under `http.paths`, leading them to pick options that are syntactically plausible but invalid in the Ingress spec.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

spec.rules.host

In Kubernetes Ingress, host-based routing is configured by specifying the `host` field directly under `spec.rules`. Each rule can define a `host` (e.g., `app1.example.com`) and the corresponding backend service. Option D correctly identifies `spec.rules.host` as the field that specifies the host for routing traffic to the appropriate service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    spec.rules.http.paths.host

    Why it's wrong here

    spec.rules.http.paths.host is invalid because the host is not declared within the paths list. In the Ingress API, each path under spec.rules[].http.paths only contains path, pathType, and a backend (service or resource); there is no host field on a path. Host-based routing is scoped to an entire rule, not to individual paths, so different Host headers require separate rules, not per-path host declarations.

  • ✗

    spec.rules.http.host

    Why it's wrong here

    spec.rules.http.host is invalid because the http object does not expose a host key. The spec.rules[].http field is an HTTPIngressRuleValue that only has a paths field (a list of HTTPIngressPath objects). The host, if present, must be declared at the rule level alongside http, not nested inside it. Putting host under http would be rejected as an unknown field by the API server.

  • ✗

    spec.tls.hosts

    Why it's wrong here

    spec.tls.hosts is not a routing mechanism; it only lists hostnames that must be covered by the TLS secret referenced in the same spec.tls entry. When a TLS secret matches the hostname, the Ingress controller terminates TLS for that host, but it does not direct which backend receives the request. Routing decisions are made solely by spec.rules[].host, so a host listed only under tls.hosts will not cause any traffic to be routed to a backend.

  • ✓

    spec.rules.host

    Why this is correct

    spec.rules.host is the correct field for host-based routing. Each rule in spec.rules can define an optional host, and the Ingress controller uses the Host header of incoming requests to match against these values. A rule without a host applies to all incoming HTTP(S) traffic. This field sits at the rule level, alongside the http field that contains the path-to-backend mappings.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.