Courseiva

CKAD Application Design and Build Practice Question

Which TWO of the following are valid ways to expose a container port in a pod spec?

⚠ Common exam trap

In the CKAD exam, the trap is that candidates confuse `containerPort` as a top-level field under `containers[]` instead of recognizing it must be nested inside `ports[]`, and they may mistakenly think Dockerfile `EXPOSE` has any effect in Kubernetes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

spec.containers[].ports[].hostPort

`spec.containers[].ports[].hostPort` is a valid field in the Pod spec that maps a container port to the host node's network interface. This allows external traffic to reach the container via the host's IP address and specified port, though it is typically used for daemon sets or host-networking scenarios rather than general service exposure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    spec.containers[].ports[].hostPort

    Why this is correct

    spec.containers[].ports[].hostPort is valid because it explicitly maps a container port to a port on the host node's network interface, enabling external traffic to reach the container via the node's IP without requiring a separate Service object. This field must be nested inside a port entry, alongside containerPort, and comes with operational caveats such as port conflicts and node scheduling constraints.

  • ✗

    spec.containers[].hostPort

    Why it's wrong here

    spec.containers[].hostPort is invalid because hostPort is not a top-level field of a container spec; it is only recognized when nested inside the ports list. Placing it directly under the container would cause a schema validation error, as the Kubernetes API expects a ports array with each entry containing fields like containerPort and optionally hostPort.

  • ✗

    spec.containers[].containerPort

    Why it's wrong here

    spec.containers[].containerPort is invalid because containerPort is likewise a field inside the ports array entry, not a direct child of the container object. It merely records the port the container listens on and is informational; by itself it does not expose the container to external traffic—that requires a Service or an associated hostPort.

  • ✗

    EXPOSE 8080 in Dockerfile

    Why it's wrong here

    EXPOSE 8080 in the Dockerfile is invalid because Dockerfile EXPOSE is only a declaration of intended ports and does not publish or expose them in Kubernetes. The pod specification governs actual networking; Kubernetes ignores EXPOSE directives and relies on the ports defined in the container manifest to configure Service routing and host mappings.

  • ✓

    spec.containers[].ports[].containerPort

    Why this is correct

    spec.containers[].ports[].containerPort is valid because it declares the port number on which the container listens inside its network namespace. This declaration is essential for a Service to select and route traffic to the correct pod, and it provides useful metadata for debugging and documentation even though it does not, by itself, open access to the outside world.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.