Courseiva
Services and Networking →hardMultiple Choice

CKAD Services and Networking Practice Question

An Ingress resource has the following annotation: 'kubernetes.io/ingress.class: nginx'. What is the purpose of this annotation?

⚠ Common exam trap

A common pitfall in CKAD is confusing the annotation that selects the Ingress controller (kubernetes.io/ingress.class) with controller-specific annotations that configure features like TLS or sticky sessions. This question tests that distinction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It specifies the Ingress controller to use (e.g., nginx)

The annotation `kubernetes.io/ingress.class: nginx` explicitly tells Kubernetes which Ingress controller should process this Ingress resource. In Kubernetes, multiple Ingress controllers (e.g., nginx, haproxy, traefik) can run in the same cluster; this annotation selects the `nginx` controller, ensuring that only that controller reads and implements the routing rules defined in the Ingress.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It sets a default backend for the Ingress

    Why it's wrong here

    This annotation does not set a default backend. In the Ingress spec, the default backend is a structured field (spec.defaultBackend) where you explicitly define a Service name and port for all requests that don't match any rules. The annotation, being simple metadata, cannot substitute for that field, and the controller ignores it for this purpose.

  • ✗

    It enables session affinity (sticky sessions)

    Why it's wrong here

    Session affinity (or sticky sessions) is not enabled by this annotation. It is configured on the Service object (e.g., service.spec.sessionAffinity: ClientIP) or via a controller-specific annotation such as nginx.ingress.kubernetes.io/affinity. The purpose of this annotation is solely to select which Ingress controller processes the resource, not to manage client-server state persistence.

  • ✗

    It enables TLS for the Ingress

    Why it's wrong here

    TLS is not enabled through this annotation. TLS termination is defined in the Ingress spec under spec.tls, where you list hostnames and reference a Secret containing the certificate and key. This annotation only indicates the controller implementation (like nginx) that should reconcile the resource; TLS settings are part of the resource's spec, not the controller-selection metadata.

  • ✓

    It specifies the Ingress controller to use (e.g., nginx)

    Why this is correct

    This annotation specifies which Ingress controller should implement the Ingress resource. For instance, kubernetes.io/ingress.class: nginx tells the ingress-nginx controller to honor this resource, especially when multiple controllers run in the same cluster. In newer Kubernetes versions, this role has been formalized by the spec.ingressClassName field backed by IngressClass objects, but the annotation remains a widely used legacy equivalent.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.