Courseiva
Services and Networking →mediumMultiple Choice

CKAD Services and Networking Practice Question

What is the purpose of the `IngressClass` resource in Kubernetes?

⚠ Common exam trap

It's easy for candidates to confuse the IngressClass with Ingress features like path routing or TLS, but the CKAD exam specifically tests that IngressClass is the mechanism to select which controller implementation handles the Ingress.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To specify which Ingress controller should implement the Ingress.

The `IngressClass` resource decouples the Ingress definition from the specific Ingress controller implementation. It allows you to specify which controller (e.g., NGINX, HAProxy, Traefik) should process the Ingress by referencing the `spec.controller` field, enabling multi-controller clusters and dynamic routing decisions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To enable path-based routing.

    Why it's wrong here

    Path-based routing is defined directly in the Ingress resource's rules, such as a host and a path mapping to a service. IngressClass, in contrast, does not contain any routing logic; it is a cluster-level identifier that tells controllers which implementation should process the Ingress. Therefore, while an Ingress may use paths, that behavior is configured in the Ingress spec, not chosen or enabled by an IngressClass.

  • ✗

    To define the TLS certificate for an Ingress.

    Why it's wrong here

    TLS certificates are Kubernetes Secrets, and an Ingress references them through its spec.tls configuration to terminate HTTPS. The IngressClass resource only carries metadata and a controller name; it has no secrets field or mechanism to store certificate material. As a result, certificate management is entirely separate from the IngressClass, which simply selects which ingress controller technology will read and act on the Ingress rules.

  • ✓

    To specify which Ingress controller should implement the Ingress.

    Why this is correct

    The IngressClass resource exists to name a specific ingress controller, such as nginx or traefik, in its spec.controller field, and it can also set parameters for that controller. An Ingress declares a class via spec.ingressClassName, and the referenced controller then picks up and implements the Ingress's routing rules. This decouples the Ingress manifest from vendor-specific controller details, allowing the cluster administrator to choose the implementation without editing each Ingress.

  • ✗

    To set the default backend for an Ingress.

    Why it's wrong here

    The default backend is an Ingress-level fallback that catches requests matching no rule, defined by spec.defaultBackend or a backend in the Ingress rules. IngressClass never configures routing or fallback behavior; it only identifies the controller to be used for that Ingress. Thus, setting a default backend is done in the Ingress object itself, not in an IngressClass, which has no such backend field.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.