CKAD Services and Networking Practice Question
Which THREE are valid ways to expose a Service externally in Kubernetes?
⚠ Common exam trap
A common mistake is assuming ClusterIP or Headless Services provide external access. ClusterIP is internal-only, and Headless Services are for service discovery without load balancing, not external exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Type: NodePort
(Type: NodePort) is correct because it exposes a Service on a static port on each Node's IP address, allowing external traffic to reach the Service by targeting <NodeIP>:<NodePort>. Option C (Type: LoadBalancer) is correct because it provisions an external load balancer in cloud environments that directs traffic to the Service. Option D (Ingress resource) is correct because it provides HTTP/HTTPS routing to Services, often using a load balancer or other entry point. Option A (Headless service) is incorrect because it is used for service discovery without a cluster IP and does not provide external access. Option E (Type: ClusterIP) is incorrect because ClusterIP is internal-only and not exposed externally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Headless service
Why it's wrong here
A headless service (spec.clusterIP: None) is designed for client-side service discovery: DNS queries return the underlying pod IPs directly rather than a stable virtual IP. Because it intentionally provides no clusterIP, no stable endpoint, and no load balancing, it cannot act as a gateway for external traffic. It only offers internal DNS-based resolution and is therefore not a valid way to expose a service outside the cluster.
- ✓
Type: NodePort
Why this is correct
A Service of type NodePort allocates a static port (default range 30000-32767) and listens on that port on every node in the cluster. External clients can reach the Service by connecting to any node's IP at that port, and kube-proxy forwards traffic to the backing pods. This works in any environment without a cloud provider, but it requires opening node ports and exposes the node's IP rather than a dedicated external endpoint.
- ✓
Type: LoadBalancer
Why this is correct
A Service of type LoadBalancer builds on NodePort: it automatically provisions a cloud-provider load balancer (for example, an AWS ELB or GCP Load Balancer) that forwards traffic to the node ports of the Service. The cloud controller assigns a stable external IP or DNS hostname, giving consumers a clean, managed entry point. This is the standard method for exposing a Service to the internet in managed Kubernetes environments, but it is only available on cloud platforms that implement the load balancer controller.
- ✓
Ingress resource
Why this is correct
Ingress is not a Service type but a separate API object that acts as a routing layer over one or more Services. An Ingress controller (such as NGINX or Traefik) is deployed inside the cluster and is itself exposed via a NodePort or LoadBalancer Service, then it routes HTTP/HTTPS requests to the correct Services based on hostnames, paths, or TLS settings. Ingress provides sophisticated layer-7 exposure, but it requires a controller and an already-exposed entry point, so it is not a simple Service-level option.
- ✗
Type: ClusterIP
Why it's wrong here
ClusterIP is the default Service type and creates a stable virtual IP that is reachable only from inside the cluster, from other Pods or Services. It is not accessible from outside the cluster because the kube-proxy rules that implement it apply only to cluster nodes and Pods. To make a ClusterIP Service externally reachable, you must add a NodePort, LoadBalancer, or Ingress in front of it; by itself, it is explicitly not a way to expose a Service externally.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.