Courseiva
Services and Networking →easyMultiple Choice

CKAD Services and Networking Practice Question

What is the purpose of the 'spec.externalName' field in a Service of type ExternalName?

⚠ Common exam trap

Many exam-takers confuse ExternalName with other service types (NodePort, LoadBalancer, ClusterIP) and think it exposes the service externally, when in fact it only provides a DNS-level alias without any network proxy or external exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To return a CNAME record pointing to an external domain

The 'spec.externalName' field in a Service of type ExternalName is used to map the service to a DNS name (e.g., 'api.example.com') rather than to a set of pods. When a client resolves the service's DNS name, Kubernetes returns a CNAME record pointing to the external domain, effectively aliasing the service to an external endpoint. This allows internal applications to access external services using a local Kubernetes service name without needing to manage endpoints manually.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To expose the service on a static port on each node

    Why it's wrong here

    A Service of type NodePort allocates a static TCP/UDP port from the default range (30000-32767) on every Kubelet node, and traffic sent to that port on any node is forwarded to the Service's cluster IP and then to the backing pods. ExternalName, in contrast, defines no ports, selectors, or endpoints; it only instructs the cluster DNS to return a CNAME record for the service name, so it never provides any node-level port binding or direct traffic routing.

  • ✗

    To expose the service using an external load balancer

    Why it's wrong here

    A Service of type LoadBalancer triggers the cloud provider (for example, AWS ELB, Azure Load Balancer, or GCP LB) to provision an external load balancer that forwards traffic to the Service's node ports or directly to pods. ExternalName does not interact with any cloud provider API, does not create a load balancer, and cannot route network traffic; it simply publishes a DNS CNAME alias for the Service name in the in-cluster DNS, so no external IP or LB resource is ever provisioned.

  • ✓

    To return a CNAME record pointing to an external domain

    Why this is correct

    ExternalName is a special Service type that maps the Service's in-cluster DNS name to an external canonical name by returning a CNAME record from CoreDNS or kube-dns. When a client resolves the Service name from inside the cluster, DNS replies with the target external domain (for example, mydb.example.com) instead of a virtual IP, and since no selectors or endpoints exist, there is no proxying or port mapping. This is ideal for providing a stable in-cluster alias to an external database or SaaS endpoint that lives outside Kubernetes.

  • ✗

    To assign a static cluster IP

    Why it's wrong here

    Assigning a static cluster IP is a feature of the ClusterIP Service type, where you can set spec.clusterIP to a specific IP address from the service CIDR to obtain a fixed virtual IP for the Service. An ExternalName Service does not allocate any cluster IP at all; its DNS name resolves to a CNAME, not to an A record with an IP, so it cannot be accessed via a virtual IP and does not support IP-based traffic. The absence of a cluster IP is fundamental to ExternalName's DNS-only operation.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.