CKAD Services and Networking Practice Question
An Ingress resource uses host-based routing. Which field in the Ingress YAML specifies the host header to match?
⚠ Common exam trap
Many candidates confuse `spec.rules[].host` with `spec.tls[].hosts` or path-level host fields, mistakenly thinking TLS host configuration also controls routing, when in fact TLS hosts only specify certificate coverage and do not affect request routing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
spec.rules[].host
In Kubernetes, host-based routing in an Ingress resource is configured using the `spec.rules[].host` field. This field specifies the fully qualified domain name (FQDN) that the Ingress controller should match against the `Host` header of incoming HTTP requests. When a request arrives with a matching `Host` header, the Ingress controller routes it to the backend service defined under that rule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
metadata.annotations['nginx.ingress.kubernetes.io/rewrite-target']
Why it's wrong here
This annotation is specific to the NGINX ingress controller and controls how the request path is rewritten before being sent to the backend service; it has no role in selecting which host header is used to match routing rules. Host-based routing is declared structurally under spec.rules, not through annotations. Even if you set this annotation, it only affects path rewriting, not which hostname triggers a particular rule.
- ✓
spec.rules[].host
Why this is correct
The spec.rules[].host field is where you define a fully qualified domain name for host-based routing; the Ingress controller compares the incoming request's Host header to this value to select the appropriate path rules. This is part of the Ingress spec and is the only field that directly determines which hostname maps to which backend configuration.
- ✗
spec.tls[].hosts
Why it's wrong here
The spec.tls[].hosts field declares the hostnames that should be served HTTPS with the provided certificate, but it is not part of the routing rules themselves. Incoming HTTP requests are routed based on the host field inside spec.rules, regardless of the TLS hosts list. Thus, spec.tls[].hosts is only for TLS termination and certificate matching, not for deciding which backend receives the request.
- ✗
spec.rules[].http.paths[].host
Why it's wrong here
Within the Ingress spec, the host property belongs to each rule (spec.rules[i].host) and is inherited by every path listed under that rule's spec.rules[].http.paths. There is no host sub-field under an individual path; path entries only contain path, pathType, and backend. Therefore, putting host inside paths is both syntactically invalid and conceptually incorrect—host-based selection happens at the rule level.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.