Courseiva
Services and Networking →hardMultiple Select

CKAD Services and Networking Practice Question

Which THREE components are typically involved when using Ingress to expose a service?

⚠ Common exam trap

The CKAD exam often tests the misconception that an external load balancer is a mandatory component of Ingress, when in fact the Ingress controller itself can run as a pod within the cluster and does not require an external LB unless the controller's Service type is LoadBalancer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ingress resource

An Ingress resource defines the routing rules for external HTTP/HTTPS traffic to services within the cluster. It specifies hostnames, paths, and the backend service to forward requests to, but it is only a configuration object. The actual traffic handling requires an Ingress controller (e.g., NGINX, Traefik) to process the Ingress resource and implement the rules, and a Service of type ClusterIP or NodePort to expose the target pods internally.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Ingress resource

    Why this is correct

    The Ingress resource is a declarative Kubernetes API object that defines external HTTP(S) routing rules, typically matching requests by hostname and URL path to specific backend Services. It serves only as a specification; it does not perform any traffic forwarding itself. Once created, an Ingress controller watches and converts these rules into actual proxy configurations. Without this resource, there is no desired state for the controller to enforce.

  • ✗

    External load balancer

    Why it's wrong here

    An external load balancer is not always part of an Ingress setup, even though many cloud environments use a Service of type LoadBalancer to expose the Ingress controller. The Ingress resource itself does not require a dedicated external LB; controllers can be exposed via NodePort, hostNetwork, or other mechanisms. The specific exposure method depends on the controller implementation and the underlying infrastructure. Therefore, an external LB is a possible implementation detail, not a core component of the Ingress pattern.

  • ✓

    Ingress controller

    Why this is correct

    The Ingress controller is the live, running component that monitors the Ingress resource and translates its routing rules into the actual traffic-routing configuration of a reverse proxy (e.g., NGINX, Traefik, HAProxy). It continuously watches the Kubernetes API and updates the proxy whenever Ingress or Service changes occur. Without a controller, an Ingress resource is inert and has no effect. This controller is what ultimately accepts external traffic and forwards it to the appropriate backend Services.

  • ✗

    NetworkPolicy

    Why it's wrong here

    NetworkPolicy is not required for Ingress functionality; it is a separate Kubernetes feature for controlling pod-to-pod traffic at the network layer (L3/L4) using label selectors and CIDR rules. Ingress operates at the application layer (L7) to route external HTTP(S) requests, whereas NetworkPolicy does not handle routing or application-aware traffic. Even if no NetworkPolicy exists, Ingress continues to work normally. NetworkPolicy might restrict ingress traffic to pods, but it is not one of the three components that make up the Ingress architecture.

  • ✓

    Service

    Why this is correct

    A Service is a critical backend component for Ingress, as it provides a stable virtual IP and a DNS name that load-balances traffic to a set of Pods. Each Ingress rule defines a backend that references a Service and a port; the Ingress controller forwards requests to that Service, which then distributes them to healthy Pods. Without a matching Service, the Ingress controller cannot resolve a destination for the routed traffic. Thus, Services are the linking layer that connects Ingress routing rules to actual workload Pods.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.