A developer runs `kubectl expose deployment web-deploy --port=80 --target-port=8080 --type=NodePort` and later wants to access the Service from outside the cluster. What is the correct way to find the external port?
`kubectl describe svc web-deploy` presents a human-readable summary that includes the NodePort mapping in its 'Port:' section, e.g., `web-deploy 80:31000/TCP`. This shows that the Service listens on port 80 internally and is exposed on port 31000 (NodePort) on every node. Because the NodePort is explicitly labeled and calculated, it is the most direct way to find the externally accessible port.
Why this answer
`kubectl expose` with `--type=NodePort` creates a Service that maps a high-port (30000-32767) on each cluster node to the target container port. The `kubectl describe svc web-deploy` output includes the `NodePort` field, which shows this externally accessible port. To reach the Service from outside the cluster, you must use the node's external IP combined with this NodePort, not the Service's cluster-internal port (80).
Exam trap
The trap here is that candidates confuse the Service's cluster-internal port (80) with the externally accessible NodePort, or mistakenly think pod IPs are stable enough for external access, when in fact the NodePort field in the Service description is the only reliable way to find the external port.
How to eliminate wrong answers
Option A is wrong because it suggests using port 80, which is the Service's cluster-internal port, not the externally accessible NodePort; NodePort services expose a random high port (30000-32767) on each node, not the Service port. Option B is wrong because pod IPs are ephemeral and only reachable from within the cluster; using a pod IP with port 8080 bypasses the Service abstraction and fails if the pod is recreated. Option D is wrong because `spec.ports[0].port` refers to the Service's cluster-internal port (80), not the NodePort; the correct field in the YAML is `spec.ports[0].nodePort`.