CKAD Services and Networking Practice Question
Which service type is used to expose a service using an external DNS name, such as a database hosted outside Kubernetes?
⚠ Common exam trap
Many exam-takers confuse ExternalName with LoadBalancer, thinking that exposing an external resource requires a load balancer, but ExternalName is specifically designed for DNS-based aliasing without any network proxy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ExternalName
ExternalName is the correct service type because it maps a Kubernetes service to an external DNS name (e.g., a database hosted outside the cluster) by returning a CNAME record with that external name. This allows pods to access the external resource using the service's DNS name without needing to know the external endpoint's IP address.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ClusterIP
Why it's wrong here
ClusterIP is the default Service type that assigns a stable virtual IP address reachable only from inside the Kubernetes cluster. It does not expose the Service to external traffic, nor does it create any DNS name that resolves outside the cluster; it exists solely for inter-Pod communication and is wrong when the goal is external exposure via a DNS name.
- ✗
NodePort
Why it's wrong here
NodePort exposes the Service on a static port (30000–32767) on every node's IP address, allowing external clients to reach it via nodeIP:nodePort. However, it relies on the node's IP rather than providing a DNS name, and it requires the client to know the node's address and port; it is not a mechanism for creating an external DNS alias.
- ✗
LoadBalancer
Why it's wrong here
LoadBalancer provisions a cloud-provider load balancer and assigns it a public external IP address, but that IP must be paired with a separate DNS record to be accessible by name. The Service itself does not generate a DNS name mapping; it merely exposes the Service at an IP:port, so it fails the requirement of exposing via an external DNS name directly.
- ✓
ExternalName
Why this is correct
ExternalName is the correct Service type because it acts as a DNS alias by returning a CNAME record that points to a fully-qualified external domain name. It requires no ClusterIP, no selector, and no port mapping; any request to the Service name is transparently redirected to the external DNS name, making it the only Service type designed specifically to expose an external DNS name.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.