Courseiva

CKAD · topic practice

Services and Networking practice questions

This domain covers Kubernetes Services, DNS resolution, Ingress, NetworkPolicy, and connectivity troubleshooting on a live cluster. CKAD tasks require you to create and inspect Services, resolve cross-namespace DNS names, configure Ingress rules and TLS, forward ports with kubectl, and verify pod-to-pod networking using imperative commands and YAML manifests.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Services and Networking

What the exam tests

What to know about Services and Networking

You must be able to create and debug Services, Ingress, and NetworkPolicy, and resolve DNS names across namespaces. The single most important thing is matching Service selectors to Pod labels and using fully qualified DNS names like svc-a.ns2.svc.cluster.local.

Creating ClusterIP, NodePort, and LoadBalancer Services with kubectl expose or YAML

Resolving Service DNS names like svc-a.ns2.svc.cluster.local across namespaces

Configuring Ingress rules, hosts, paths, and TLS secrets for HTTP routing

Using kubectl port-forward to reach Pods and Services from localhost

Watch out for

Common Services and Networking exam traps

  • ▸Assuming a Service in another namespace resolves by short name; cross-namespace DNS requires the full name including namespace
  • ▸Forgetting that a Service selector must match Pod labels exactly, so endpoints stay empty when labels differ
  • ▸Writing Ingress paths without the correct pathType, causing the rule to be rejected or not route traffic

Practice set

Services and Networking questions

20 questions · select your answer, then reveal the explanation

Question 1easymultiple choice
Read the full DNS explanation →

An application requires Pods to communicate using hostNetwork: true. Which Kubernetes resource is still necessary for stable DNS names?

Question 2mediummultiple choice
Read the full DNS explanation →

You have deployed a microservices application in a Kubernetes cluster. One of the services, 'payment-service', needs to be accessed by other services within the cluster via a stable DNS name. You create a Service of type ClusterIP named 'payment' with selector app=payment. However, when you try to curl http://payment from another Pod, the connection times out. You verify that the Pods backing 'payment-service' are running and ready, and the Endpoints object lists the correct Pod IPs. You also confirm that the Pods are listening on port 8080, and the Service defines targetPort: 8080. The cluster uses a standard CNI plugin (Calico) and DNS is provided by CoreDNS. What is the most likely cause of the timeout?

A DevOps engineer notices that traffic to a Service named 'api' is not being forwarded to newly created pods. The Service selects pods with label 'app: api'. The pods are running and have the correct label. However, the Service's endpoints list does not include the new pods. What is the most likely cause?

During a security audit, it is discovered that a pod running a database is accessible from any other pod in the cluster. The database should only be accessible by pods with label 'role: backend'. Which resource should be applied to enforce this restriction?

A developer deploys a web application as a Deployment named 'web-app' with 3 replicas. The application listens on port 8080 and should be accessible from within the cluster via the service name 'web-svc' on port 80. Which Service YAML correctly exposes the application?

A DevOps engineer is setting up network policies in a Kubernetes cluster. The goal is to allow traffic from pods with label 'role=frontend' to pods with label 'role=backend' on TCP port 8080, and deny all other ingress to backend pods. Which two components are necessary to implement this? (Choose two.)

Match each YAML key in a Deployment manifest to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

API version of the resource (e.g., apps/v1)

Desired number of pod instances

Labels used to identify pods managed by the deployment

Labels assigned to pods created by the template

Container image to run

Match each Kubernetes term to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Runs before app containers; for setup tasks

Helper container that runs alongside the main container

Pod managed directly by the kubelet without API server

Temporary container for debugging running pods

Pod with multiple containers sharing the same network and storage

Question 9mediummultiple choice
Review the full routing breakdown →

You have an Ingress resource that routes traffic to two services: 'app1' and 'app2'. The requirement is that traffic for 'app.example.com' goes to app1, and traffic for any other host goes to app2. Which Ingress specification correctly achieves this?

Question 10mediummultiple choice
Read the full DNS explanation →

A developer creates a Service named 'backend' in namespace 'default'. The service targets pods with label 'app: backend'. From within a pod in the same namespace, which DNS name resolves to the service's ClusterIP?

A NetworkPolicy allows ingress traffic from pods with label 'role: frontend' in the same namespace. Which podSelector is correct?

A developer wants to test a service locally using kubectl. Which command forwards local port 8080 to the service's port 80?

Which TWO are valid ways to create a Service in Kubernetes?

Which kubectl command creates a Service of type ClusterIP named 'my-service' that exposes port 80 on a set of pods selected by label 'app: web'?

Question 15mediummultiple choice
Read the full DNS explanation →

You create a Service named 'backend' in namespace 'prod'. A pod in namespace 'dev' tries to reach the service using the DNS name 'backend.prod.svc.cluster.local'. The pod cannot resolve the name. What is the most likely cause?

You are tasked with creating a NetworkPolicy that denies all ingress traffic to pods in the 'db' namespace by default. Which YAML snippet correctly implements this?

You run 'kubectl port-forward pod/my-pod 8080:80' and try to access 'http://localhost:8080', but the connection is refused. The pod is running and port 80 is open. What is the most likely issue?

You have a NetworkPolicy that allows ingress from pods with label 'app: frontend' in any namespace, and also allows ingress from the IP range '10.0.0.0/8'. The policy is not working as expected. Which YAML snippet correctly implements both requirements?

Which command creates a Service named 'web' of type ClusterIP that selects pods with label 'tier: frontend' and exposes port 80?

Which TWO of the following are valid rules for a NetworkPolicy that allows egress traffic from pods with label 'app: worker' to the external IP range '192.168.0.0/16' on port 53 UDP? (Select 2)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Services and Networking sessions

Start a Services and Networking only practice session

Every question in these sessions is drawn from the Services and Networking domain — nothing else.

Related practice questions

Related CKAD topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CKAD exam test about Services and Networking?
You must be able to create and debug Services, Ingress, and NetworkPolicy, and resolve DNS names across namespaces. The single most important thing is matching Service selectors to Pod labels and using fully qualified DNS names like svc-a.ns2.svc.cluster.local.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Services and Networking questions in a focused session?
Yes — the session launcher on this page draws every question from the Services and Networking domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CKAD topics?
Use the topic links above to move to related areas, or go back to the CKAD question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CKAD exam covers. They are not copied from any real exam or dump site.