CKAD Services and Networking Practice Question
Which TWO of the following are true about headless services? (Select 2)
⚠ Common exam trap
A common misconception is that headless services cannot have selectors, but they can; the key difference is that without a selector, you must manually manage Endpoints or use ExternalName, while with a selector, DNS returns pod IPs directly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS returns multiple A records, one for each pod's IP
Headless services (with clusterIP: None) cause DNS to return multiple A records, one for each pod's IP address, rather than a single virtual IP. This allows direct pod-to-pod DNS resolution, which is essential for stateful applications like databases that need to discover individual pod endpoints.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DNS returns multiple A records, one for each pod's IP
Why this is correct
In a headless service, no cluster IP is allocated, so the DNS name for the service resolves directly to the set of pod IPs that match its selector. Kubernetes DNS, typically CoreDNS, returns a separate A record for each matching pod IP, allowing clients to discover and connect to each pod independently. This behavior is essential for peer discovery in StatefulSet-based distributed systems, where each replica must be addressed individually.
- ✓
They set 'clusterIP: None' in the service spec
Why this is correct
Setting `clusterIP: None` in the Service specification is the explicit way to define a headless service. This field tells Kubernetes to skip allocating a stable virtual IP and to skip creating a kube-proxy-managed load balancer. Instead, the service exists purely for DNS-based service discovery, publishing the IP addresses of the pods selected by its selector so that clients can query them directly.
- ✗
They provide a stable virtual IP for load balancing
Why it's wrong here
This statement is incorrect because a headless service deliberately avoids providing a virtual IP; that is the entire point of setting `clusterIP: None`. With a regular ClusterIP service, a stable VIP is allocated and kube-proxy load-balances traffic among the pods. A headless service returns the actual pod IPs via DNS, so there is no single virtual IP to act as a load-balancing frontend.
- ✗
They cannot have a selector
Why it's wrong here
Headless services are fully allowed to have a selector, and in fact, most do. When a selector is present, Kubernetes automatically creates an Endpoints object listing the matching pod IPs, which is what enables the DNS server to return multiple A records. Only when no selector is defined does a headless service rely on a manually created Endpoints resource to point to external IPs, but this is an edge case, not a restriction.
- ✗
They are used exclusively with Deployments
Why it's wrong here
Headless services are not exclusive to any workload type; they can be used with Deployments, DaemonSets, or plain pods. However, they are especially valuable for StatefulSets because each stateful pod needs a stable, predictable network identity to support peer discovery and direct pod-to-pod communication. Since Deployments commonly use a Service as a load-balanced frontend, headless services are far more often associated with StatefulSets, making the claim of exclusivity incorrect.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.