Courseiva
Services and Networking →easyMultiple Choice

CKAD Services and Networking Practice Question

Which of the following is true about headless services?

⚠ Common exam trap

Many candidates assume all services must have a Cluster IP and perform load balancing, but headless services explicitly disable that to provide direct pod IP resolution for stateful workloads.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It has no cluster IP; DNS returns the IPs of the pods

A headless service is created by setting `clusterIP: None` in the Service spec. Because it has no Cluster IP, kube-proxy does not create any load-balancing rules for it. Instead, the DNS lookup for the service name returns the IP addresses of all ready pods backing the service, allowing direct pod-to-pod communication without a proxy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It performs round-robin load balancing across pods

    Why it's wrong here

    A headless service sets clusterIP: None, so there is no Virtual IP (VIP) and kube-proxy creates no load-balancing rules. When clients resolve the service DNS name, they receive all ready pod IPs instead of a single VIP, so round-robin load balancing is not performed by the service. Any balancing must be implemented by the client or an intermediary component such as an ingress controller, not by the headless service itself.

  • ✓

    It has no cluster IP; DNS returns the IPs of the pods

    Why this is correct

    In a headless service, you explicitly set clusterIP: None, which removes the stable cluster IP from the Service object. The DNS name then resolves not to a VIP but to the actual IP addresses of all backing pods selected by the service. This is the defining behavior of headless services: DNS returns multiple A records, one per pod endpoint, enabling direct pod-to-pod communication.

  • ✗

    It provides a single DNS record for the service

    Why it's wrong here

    A headless service does not create a single DNS record for the Service; instead, the DNS system generates multiple A records, one for each selected pod endpoint. Because there is no cluster IP, a single-record VIP lookup is impossible. Headless services can also publish SRV records specifying ports and weights, so the DNS answer set includes per-pod records rather than one aggregate record.

  • ✗

    It must not have a selector

    Why it's wrong here

    Headless services are not required to omit a selector; a selector is completely optional. When a selector is present, the EndpointSlice controller populates endpoints with the matching pod IPs, and DNS returns those IPs. When no selector is present (e.g., for external services), DNS returns the manually defined endpoints, but the service is still headless as long as clusterIP is None. The selector only controls which endpoints are collected, not whether the service is headless.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.