CKAD Services and Networking Practice Question
Which THREE commands can be used to list the endpoints of a Service named 'my-svc'?
⚠ Common exam trap
Many exam-takers think `kubectl get pods -l app=my-svc` shows endpoints, but it only shows pods matching a specific label, not the actual endpoint IP:Port pairs that the Service routes to, and the label selector may not match the Service's selector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl describe svc my-svc
`kubectl describe svc my-svc` displays detailed information about the service, including the list of endpoints (IP:Port pairs) that the service routes traffic to. Options D and E are also correct because `kubectl get ep my-svc` and `kubectl get endpoints my-svc` are equivalent commands that directly list the Endpoints resource associated with the service. All three commands provide the endpoint information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl get networkpolicy
Why it's wrong here
kubectl get networkpolicy is incorrect because it queries NetworkPolicy objects, which are cluster-level firewall rules governing traffic between pods. These policies define allow/deny rules using pod selectors, namespace selectors, and CIDRs, but they contain no resolved IP addresses or port mappings for a Service. Run this command and you'll see names of policies, not endpoint data, so it provides zero information about the Service's current backends.
- ✗
kubectl get pods -l app=my-svc
Why it's wrong here
kubectl get pods -l app=my-svc is wrong because it lists pod objects that match that label selector, not Service endpoints. Even if those pods happen to be behind the Service, the command only shows pod names, ready status, and restart counts—not the port-to-IP bindings that constitute an Endpoints object. Moreover, the Service's actual selector might not be 'app=my-svc', or it could use no selector at all, making this an unreliable and indirect way to discover endpoints.
- ✓
kubectl describe svc my-svc
Why this is correct
kubectl describe svc my-svc is correct because the describe output includes an 'Endpoints' section, which lists the current set of IP:port pairs that the Service routes traffic to. It presents this information in a human-readable format alongside the Service's selector, port mappings, and type. However, because describe is meant for efficient troubleshooting, it shows endpoints in a summarized, non-printable way, which is not ideal for scripting, but perfectly valid for a quick visual inspection.
- ✓
kubectl get ep my-svc
Why this is correct
kubectl get ep my-svc is correct because 'ep' is a kubectl shortcut for the 'endpoints' resource. This command retrieves the raw Endpoints object associated with the Service, displaying subsets that contain addresses and ports. Using the short alias is efficient, but note that 'ep' is an abbreviation, not a different resource—it returns exactly the same API object as 'kubectl get endpoints'. This approach is better than describe when you need to feed the output into a script or parser.
- ✓
kubectl get endpoints my-svc
Why this is correct
kubectl get endpoints my-svc is correct because it accesses the Endpoints API resource by its full name, returning the exact list of pod IPs and ports that serve the Service. Unlike describe, which summarizes, this command provides the raw, structured object, making it reliable for automation and troubleshooting. The output may show multiple subsets if the Service has multiple ports or if endpoints are spread across address groups, giving you the complete end-to-end connection details.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.