CKAD Services and Networking Practice Question
Which TWO of the following are valid Ingress path types? (Select 2)
⚠ Common exam trap
The CKAD exam often tests the distinction between path types and host-based routing, leading candidates to confuse wildcard hostnames (e.g., `*.example.com`) with path types, or to assume regex/glob patterns are supported when they are not.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Exact
In Kubernetes Ingress, the `spec.rules.http.paths[].pathType` field supports two valid types: `Exact` and `Prefix`. `Exact` matches the URL path exactly, case-sensitive, and is used when you need a precise match without any wildcard or prefix behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Glob
Why it's wrong here
Glob patterns like '*' are common in file matching, but the Kubernetes Ingress API does not define 'Glob' as a valid pathType value. The networking.k8s.io/v1 specification only recognizes Exact, Prefix, and ImplementationSpecific, so a manifest with pathType: Glob would be rejected by the API server. Glob-style matching is not part of the core Ingress contract and would have to be handled via ImplementationSpecific extensions.
- ✓
Exact
Why this is correct
Exact is one of the two valid standard pathType values in the Kubernetes Ingress spec. It matches only the precise URL path, and matching is case-sensitive, meaning /foo does not match /Foo or /foo/. This pathType is ideal for explicit API endpoints where a route must be limited to a single URI without inadvertently catching deeper subpaths.
- ✗
Wildcard
Why it's wrong here
Wildcard is not a valid pathType in Kubernetes Ingress. Unlike configuration systems that allow '*' as a catch-all, the Ingress API does not have a distinct wildcard pathType. The semantics of Prefix and Exact already cover typical wildcard use cases; for example, a Prefix of / effectively matches all paths, so a separate wildcard type is unnecessary and unsupported.
- ✗
Regex
Why it's wrong here
Regex is not a valid pathType in the core Kubernetes Ingress API. While many ingress controllers like NGINX and Traefik support regular expressions through annotations or the ImplementationSpecific pathType, the standard Ingress spec deliberately omits Regex to ensure consistent behavior across controllers. Declaring pathType: Regex would be rejected by the API server, and regex-based routing is left to controller-specific extensions.
- ✓
Prefix
Why this is correct
Prefix is the other valid standard pathType in Kubernetes Ingress and matches based on slash-delimited path segments. A request to /foo/bar matches a Prefix of /foo because the segments align at a boundary, but /foobar would not match because the next segment is 'foobar', not 'foo'. This pathType is the most commonly used, as a single rule can cover an entire subtree of paths beneath a common base.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.