CKAD Services and Networking Practice Question
What annotation is required on an Ingress resource to use a specific IngressClass (e.g., 'nginx')?
⚠ Common exam trap
Watch out — candidates often confuse the annotation `kubernetes.io/ingress.class` with the `spec.ingressClassName` field or invent non-existent annotations like `kubernetes.io/ingress-type`, leading them to pick a plausible-sounding but incorrect option.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubernetes.io/ingress.class: nginx
The `kubernetes.io/ingress.class` annotation is the legacy method to specify the IngressClass for an Ingress resource. This annotation tells the Ingress controller (e.g., nginx) which controller should process the Ingress rules. In Kubernetes 1.18+, the preferred method is the `spec.ingressClassName` field, but the annotation is still widely supported for backward compatibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubernetes.io/ingress-type: nginx
Why it's wrong here
This annotation key does not conform to any Kubernetes or Ingress controller standard. The official annotation for specifying an IngressClass is `kubernetes.io/ingress.class`, and this invented key will be silently ignored by ingress controllers. Choosing this indicates a misunderstanding of the annotation naming convention and should be avoided.
- ✓
kubernetes.io/ingress.class: nginx
Why this is correct
This is the correct, historically standard annotation used to tell an ingress controller which IngressClass resource to use for configuring routing. Although the Kubernetes Ingress API now provides the `ingressClassName` field, this annotation remains widely supported by controllers like NGINX Ingress. It must exactly match the name of an IngressClass object in the cluster.
- ✗
ingress.kubernetes.io/class: nginx
Why it's wrong here
While this key uses the "kubernetes.io" suffix, the prefix "ingress.kubernetes.io" is not an official Kubernetes annotation namespace. The canonical annotation is `kubernetes.io/ingress.class`; this variant is not recognized by standard ingress controllers and may be specific to obscure vendor implementations. Relying on it can break portability across clusters.
- ✗
kubernetes.io/class: nginx
Why it's wrong here
Dropping the `ingress` resource segment makes this annotation unrecognizable to ingress controllers for class selection. The full key `kubernetes.io/ingress.class` embeds the resource type in the annotation name, and without that segment the annotation will be ignored. It might be used by unrelated tools, but it will not affect Ingress routing.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.