CKAD Services and Networking Practice Question
Which Service type is used to expose a Service externally using a cloud provider's load balancer?
⚠ Common exam trap
Candidates often confuse NodePort with LoadBalancer, thinking NodePort provides external exposure via a cloud load balancer, but NodePort only opens a port on each node's IP and does not integrate with cloud provider load balancers automatically.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
LoadBalancer
The LoadBalancer service type provisions an external load balancer from the underlying cloud provider (e.g., AWS ELB, GCP TCP/UDP Load Balancer) and assigns a public IP or DNS name to route external traffic to the Service's ClusterIP and NodePort. This is the correct choice because it directly exposes the Service externally via the cloud provider's infrastructure, unlike other types that either expose internally or require manual configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
NodePort
Why it's wrong here
NodePort is wrong because it exposes the Service on a static port (30000-32767) on every node's IP address, but it does not create a cloud load balancer. Clients must reach a node IP directly, which is rarely suitable for production due to unstable node IPs and lack of automatic failover. NodePort is typically used only as a building block for the LoadBalancer type or for debugging.
- ✓
LoadBalancer
Why this is correct
LoadBalancer is correct because it instructs the cloud provider (e.g., AWS, GCP, Azure) to provision an external load balancer and assign a stable, publicly reachable IP address or DNS name. This traffic is automatically forwarded to the Service's backend pods, abstracting away node IPs and providing health checks and auto-scaling of the underlying infrastructure. It is the standard way to expose a Service to internet-facing external clients.
- ✗
ExternalName
Why it's wrong here
ExternalName is wrong because it does not expose a Service with selectors and endpoints; instead, it returns a CNAME record that points to an external DNS name, such as a database hosted outside the cluster. It is used to provide an internal alias for external services, not to receive incoming external traffic or create a load balancer. Therefore, it cannot serve the purpose of exposing a Service externally.
- ✗
ClusterIP
Why it's wrong here
ClusterIP is wrong because it assigns a stable virtual IP address that is only reachable from within the cluster, not from outside. This is the default Service type and is intended for internal communication between pods, such as front-end to back-end. Since it lacks any external network exposure, it cannot be used to make a Service available to external clients.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.