Courseiva
Services and Networking →mediumMultiple Select

CKAD Ingress Controller Practice Question

Which TWO items are required for Ingress to work correctly in a Kubernetes cluster?

⚠ Common exam trap

The trap is that TLS is not mandatory; only an Ingress controller and at least one rule are required. Candidates often think TLS is required or that a default backend is necessary, but it is not.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

At least one rule specifying either host or path

For Ingress to work correctly, the cluster must have a running Ingress controller to process Ingress resources. At least one rule specifying a host or path is required to define routing logic. A TLS secret is optional for HTTPS termination, not mandatory. Without these two components, the Ingress will not route traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    At least one rule specifying either host or path

    Why this is correct

    At least one rule specifying either a host or path is essential because the Ingress resource is fundamentally a routing table; without a rule, there is no destination for incoming traffic. Each rule defines a mapping from an HTTP host and/or URL path to a backend service, and this mapping is what the controller uses to proxy requests. A bare Ingress with no rules would be inert and could not route anything.

  • ✓

    An Ingress controller running in the cluster

    Why this is correct

    An Ingress controller must be running in the cluster because the Ingress resource is merely a declarative object that has no inherent networking capabilities. The controller watches for Ingress resources and programs the underlying proxy (such as nginx or HAProxy) to implement the desired routing rules. Without a controller, creating an Ingress has no effect and traffic will not be routed.

  • ✗

    A TLS secret for HTTPS termination

    Why it's wrong here

    A TLS secret is only needed when you explicitly configure HTTPS termination via the Ingress's tls block; it is entirely optional for basic HTTP routing. Ingress works perfectly on port 80 without any secret, and you can also terminate TLS using other mechanisms. Therefore, the absence of a TLS secret does not prevent Ingress from functioning.

  • ✗

    A LoadBalancer service for the backend

    Why it's wrong here

    A LoadBalancer service for the backend is unnecessary because the Ingress controller routes traffic directly to the backend's ClusterIP, which is already reachable within the cluster. The Ingress itself acts as the external load balancer entry point; adding a LoadBalancer to the backend would create an unneeded extra layer and potential cost.

  • ✗

    A default backend service

    Why it's wrong here

    A default backend service is not mandatory for Ingress to function; it only provides a catch-all for requests that do not match any rule. If omitted, unmatched requests simply receive a 404 response from the Ingress controller. The core requirement is having at least one routing rule, not a default fallback destination.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.