Courseiva
Services and Networking →hardMultiple Select

CKAD Services and Networking Practice Question

Which THREE components are required for a basic Ingress to route HTTP traffic to a Service? (Choose three.)

⚠ Common exam trap

CNCF often tests the misconception that a Deployment is mandatory for Ingress to work, but the Ingress only requires a Service to route to, and the underlying Pods can be created by any workload resource (e.g., a ReplicaSet or even a standalone Pod).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A Service of type ClusterIP or NodePort

Option B is correct because an Ingress routes external HTTP traffic to a backing Service, which must exist as a ClusterIP or NodePort Service that selects the application's pods and exposes the target port. Option D is correct because the Ingress resource YAML defines the routing rules (host, path, and backend Service name/port) that the controller reads to configure HTTP routing. Option E is correct because an Ingress resource has no effect on its own; an Ingress controller such as nginx-ingress watches Ingress objects and programs the actual HTTP load balancer/proxy. Option A is not required because the Ingress only needs a Service with endpoints, and those endpoints can come from any workload controller or even manually managed pods, not specifically a Deployment. Option C is not required because NetworkPolicy is an optional security control; basic Ingress routing works without any NetworkPolicy as long as the controller can reach the Service endpoints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A Deployment of the application

    Why it's wrong here

    While a Deployment is responsible for managing the application's Pod replicas and ensuring the desired state, it is a workload controller, not a networking endpoint. The Ingress controller routes traffic to a Service, which then selects and load-balances to the Pods created by the Deployment. An Ingress backend must reference a Service's DNS name and port, because a Deployment has no stable ClusterIP or hostname to route to.

  • ✓

    A Service of type ClusterIP or NodePort

    Why this is correct

    An Ingress resource forwards HTTP requests to a backend Service, which must exist and select the target pods; a ClusterIP Service is sufficient because the Ingress controller performs the proxying, so NodePort or LoadBalancer exposure is not strictly needed for basic routing.

  • ✗

    A NetworkPolicy allowing traffic from the Ingress controller

    Why it's wrong here

    A NetworkPolicy that explicitly allows traffic from the Ingress controller is an optional security measure, not a building block of Ingress functionality. In a default Kubernetes cluster, all traffic is permitted unless a NetworkPolicy is in place to restrict it. The Ingress controller can reach the Service and Pods without any policy unless a strict default-deny configuration has been added, in which case a policy becomes necessary for routing to work.

  • ✓

    An Ingress resource YAML file

    Why this is correct

    The Ingress resource YAML file is the declarative definition of the routing rules: it specifies hosts, URL paths, and which backend Service should receive matching traffic. This API object (in networking.k8s.io/v1) is what the Ingress controller watches and uses to program the underlying proxy configuration. Without an Ingress resource, the controller has no instructions and cannot route any external traffic into the cluster.

  • ✓

    An Ingress controller (e.g., nginx-ingress)

    Why this is correct

    An Ingress controller is the actual software implementation (such as nginx-ingress or AWS Load Balancer Controller) that watches the Kubernetes API for Ingress resources and configures its load balancer accordingly. It runs as a set of Pods or a daemon in the cluster, often deployed with its own Service or DaemonSet, and it publishes or updates the routing rules. Without a running controller, an Ingress resource is inert—the API object is stored but never acted upon.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.