Courseiva
Services and Networking →easyMultiple Choice

CKAD Services and Networking Practice Question

Which command exposes a deployment named 'web' as a ClusterIP service on port 80?

⚠ Common exam trap

Candidates often confuse `kubectl expose` with `kubectl create service clusterip`. The key difference: `expose` automatically derives the label selector from the deployment's pod template, ensuring the service matches the deployment's pods. `create service clusterip` sets a generic selector (e.g., `app=<service-name>`) based on the service name; this may or may not match the deployment's labels, so it may not expose the deployment correctly unless the deployment happens to use the same labels.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl expose deployment web --port=80

`kubectl expose deployment web --port=80` creates a ClusterIP service by default, which exposes the deployment on port 80 within the cluster. The `expose` command automatically selects the deployment's pod labels and creates a service that maps port 80 to the target port (defaulting to the same port).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl create service clusterip web --port=80

    Why it's wrong here

    kubectl create service clusterip web --port=80 is wrong because it creates a ClusterIP service manifest with no selector field. A Service requires a selector to identify the pods it should route traffic to; without a matching selector, the Endpoints controller cannot populate the service's endpoints, leaving the ClusterIP with no backing pods. Unlike kubectl expose, which automatically copies the deployment's pod selector, this imperative command leaves the service selector-less unless you manually specify --tcp or edit the service afterward, so traffic to this ClusterIP would never reach the deployment's pods.

  • ✓

    kubectl expose deployment web --port=80

    Why this is correct

    kubectl expose deployment web --port=80 is correct because kubectl expose is the canonical command for generating a Service from an existing workload resource, and it defaults to type ClusterIP. It automatically reads the deployment's label selector and applies those same labels to the service's spec.selector, ensuring the Service immediately routes traffic to the deployment's pods. The --port=80 flag sets the service port, and since --target-port is omitted, it defaults to the same value (80), so pod port 80 receives the traffic. This provides the simplest, standard way to create a ClusterIP service that exposes the deployment.

  • ✗

    kubectl run web --expose --port=80

    Why it's wrong here

    kubectl run web --expose --port=80 is wrong because kubectl run is intended to create a workload (a pod or deployment) from a command, not to expose an existing resource. If a deployment named web already exists, this command either conflicts with the existing resource or creates a separate, new workload with the same name, depending on the Kubernetes version and policy. The --expose flag creates a Service tied to the newly created workload's labels, not to the existing deployment's pods. Even in versions where kubectl run creates a deployment, it would replace or fail on the existing deployment, making it neither safe nor idiomatic for exposing an already-managed deployment.

  • ✗

    kubectl expose deployment web --port=80 --type=NodePort

    Why it's wrong here

    kubectl expose deployment web --port=80 --type=NodePort is wrong for this question because explicitly setting --type=NodePort changes the Service type from the default ClusterIP to NodePort. A NodePort service exposes the application on a static port on every node in the cluster, making it accessible from outside the cluster, which is beyond the scope of internal ClusterIP access. While a NodePort service also has a ClusterIP assigned, the question specifically asks for a ClusterIP service, and overriding the type defeats that purpose. The default behavior of kubectl expose (without a --type flag) is ClusterIP, so adding --type=NodePort creates a service that is primarily NodePort, not a plain ClusterIP.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.