Courseiva
Services and Networking →hardMultiple Select

CKAD Services and Networking Practice Question

Which THREE of the following are valid use cases for a Headless Service (clusterIP: None)?

⚠ Common exam trap

Many exam-takers confuse the purpose of a Headless Service with a regular ClusterIP Service, mistakenly thinking it can provide external exposure or a stable virtual IP, when in fact it is designed for direct Pod-to-Pod discovery without load balancing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Discovering all Pod IPs via DNS A/AAAA records

A Headless Service (clusterIP: None) does not provide a virtual IP or load balancing. Instead, DNS queries return A/AAAA records containing the IP addresses of all healthy Pods selected by the service. This allows clients to discover and connect directly to individual Pod IPs, which is essential for stateful applications or custom discovery patterns.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Discovering all Pod IPs via DNS A/AAAA records

    Why this is correct

    A headless Service (spec.clusterIP: None) yields DNS A/AAAA records populated with the IP addresses of each ready backing Pod instead of a single virtual IP. This enables clients to resolve every instance's address directly, which is essential for peer discovery and client-side service discovery patterns. Because the records reflect current ready endpoints, they also react to Pod churn and scale events.

  • ✗

    Exposing the service externally via cloud load balancer

    Why it's wrong here

    Headless Services intentionally omit a ClusterIP, and a Service of type LoadBalancer requires a ClusterIP to allocate a cloud provider's external load balancer (or a stable VIP) that forwards to the Endpoints. Setting type: LoadBalancer on a headless Service is not a supported valid use case; external exposure should rely on a regular ClusterIP/NodePort or an Ingress backed by a Service.

  • ✓

    StatefulSet pod DNS (e.g., pod-0.svc.namespace.svc.cluster.local)

    Why this is correct

    With StatefulSets, each Pod has an ordinal identity (pod-0, pod-1, ...) and a stable hostname. A headless Service (with matching selector) publishes DNS SRV and A records that map each hostname to the Pod's IP as pod-0.my-svc.namespace.svc.cluster.local, giving every StatefulSet member an individual, predictable DNS name. This is fundamental to database clustering and any workload requiring stable network identities.

  • ✓

    Implementing a custom load balancing algorithm

    Why this is correct

    When a client performs a DNS lookup on a headless Service name, it receives the complete set of Pod IPs (subject to readiness) rather than a kube-proxy-randomized VIP. This lets the application implement its own load-balancing strategy — e.g., weighted round robin, least-loaded selection, or session affinity based on business logic — rather than relying on kube-proxy's default random distribution. It is a legitimate design pattern for custom client-side load balancing.

  • ✗

    Providing a stable virtual IP for load balancing

    Why it's wrong here

    A headless Service has spec.clusterIP set to None, meaning no stable virtual IP is assigned and kube-proxy does not create cluster-wide iptables/IPVS rules for it. Therefore it cannot provide a stable VIP for traffic clustering or simple round-robin load balancing at the cluster layer; those behaviors require a normal ClusterIP Service. Choosing a headless Service specifically removes the stable virtual IP guarantee.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.