CKAD Services and Networking Practice Question
Which of the following is true about headless services?
⚠ Common exam trap
Many candidates assume all services must have a Cluster IP and perform load balancing, but headless services explicitly disable that to provide direct pod IP resolution for stateful workloads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It has no cluster IP; DNS returns the IPs of the pods
A headless service is created by setting `clusterIP: None` in the Service spec. Because it has no Cluster IP, kube-proxy does not create any load-balancing rules for it. Instead, the DNS lookup for the service name returns the IP addresses of all ready pods backing the service, allowing direct pod-to-pod communication without a proxy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It performs round-robin load balancing across pods
Why it's wrong here
A headless service sets clusterIP: None, so there is no Virtual IP (VIP) and kube-proxy creates no load-balancing rules. When clients resolve the service DNS name, they receive all ready pod IPs instead of a single VIP, so round-robin load balancing is not performed by the service. Any balancing must be implemented by the client or an intermediary component such as an ingress controller, not by the headless service itself.
- ✓
It has no cluster IP; DNS returns the IPs of the pods
Why this is correct
In a headless service, you explicitly set clusterIP: None, which removes the stable cluster IP from the Service object. The DNS name then resolves not to a VIP but to the actual IP addresses of all backing pods selected by the service. This is the defining behavior of headless services: DNS returns multiple A records, one per pod endpoint, enabling direct pod-to-pod communication.
- ✗
It provides a single DNS record for the service
Why it's wrong here
A headless service does not create a single DNS record for the Service; instead, the DNS system generates multiple A records, one for each selected pod endpoint. Because there is no cluster IP, a single-record VIP lookup is impossible. Headless services can also publish SRV records specifying ports and weights, so the DNS answer set includes per-pod records rather than one aggregate record.
- ✗
It must not have a selector
Why it's wrong here
Headless services are not required to omit a selector; a selector is completely optional. When a selector is present, the EndpointSlice controller populates endpoints with the matching pod IPs, and DNS returns those IPs. When no selector is present (e.g., for external services), DNS returns the manually defined endpoints, but the service is still headless as long as clusterIP is None. The selector only controls which endpoints are collected, not whether the service is headless.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.