Courseiva
Services and Networking →easyMultiple Choice

CKAD Services and Networking Practice Question

Exhibit

Refer to the exhibit.
```yaml
apiVersion: v1
kind: Service
metadata:
  name: my-service
spec:
  type: NodePort
  selector:
    app: my-app
  ports:
    - port: 80
      targetPort: 8080
      nodePort: 30007
```

Refer to the exhibit. A user has created the Service shown. The application pods listen on port 8080. Which port should an external client use to access the application from outside the cluster?

⚠ Common exam trap

Test-takers frequently confuse the Service port (80) or targetPort (8080) with the externally accessible port, failing to recognize that only the NodePort (30007) is reachable from outside the cluster.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

30007

The Service is of type NodePort, which exposes the application on a static port (30007) on each node's IP address. External clients can access the application by hitting any cluster node's IP on port 30007, which forwards traffic to the Service's ClusterIP on port 80, then to the pods on port 8080.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    8080

    Why it's wrong here

    The value 8080 is the Service's targetPort, which identifies the container port on the pod. It is only used internally by the Service to route traffic to the backend application, not as a port exposed on the node. External clients must connect to the nodePort 30007 rather than 8080, since targetPort is never directly reachable from outside the cluster.

  • ✗

    80

    Why it's wrong here

    Port 80 is the Service's port, which defines the virtual ClusterIP port that other in-cluster resources use to reach the Service. This port is not bound to the host network interface and does not accept traffic from outside the cluster. NodePort services map an external nodePort to this internal service port, but the service port itself remains private to the cluster.

  • ✓

    30007

    Why this is correct

    30007 is the correct external access port because the Service is of type NodePort and explicitly declares nodePort: 30007. This port is opened on every node in the cluster, and Kubernetes routes any traffic sent to <nodeIP>:30007 to the Service's port 80, then to targetPort 8080. It falls within the default 30000-32767 nodePort range, making it a valid externally reachable endpoint.

  • ✗

    30000

    Why it's wrong here

    30000 is not defined anywhere in the Service manifest, and unlike the explicitly set nodePort 30007, there is no automatic allocation that would choose 30000 in this case. While 30000 is the lower bound of Kubernetes' default nodePort range and could be auto-assigned in a different Service, the actual configuration clearly selects 30007. Assuming 30000 is reachable would be incorrect because the Service does not bind to that port.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.