Courseiva
Services and Networking →mediumMultiple Select

CKAD Services and Networking Practice Question

Which TWO of the following are valid ways to expose a Deployment named 'web' as a Service?

⚠ Common exam trap

The CKAD exam often tests the distinction between creating a Service versus exposing an existing workload, so the trap here is that candidates may confuse `kubectl create service` (which requires explicit selector configuration) with `kubectl expose` (which automatically derives the selector from the resource), leading them to incorrectly select option E as a valid method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl expose deployment web --port=80

`kubectl expose deployment web --port=80` creates a Service that automatically selects Pods based on the labels defined in the Deployment's pod template. This command generates a ClusterIP Service that maps port 80 on the Service to the target port (defaulting to the same port) on the selected Pods, providing a stable network endpoint for the Deployment's replicas.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    kubectl expose deployment web --port=80

    Why this is correct

    kubectl expose deployment web --port=80 creates a Service of type ClusterIP by default, using the deployment's selector (pod template labels) to target the pods. It validates the deployment exists and uses the container port if --target-port not specified, defaulting to --port. This is a declarative-ish imperative command that creates a Service resource, exposing the deployment's pods to other cluster clients.

  • ✗

    kubectl port-forward deployment/web 8080:80

    Why it's wrong here

    kubectl port-forward is a debugging utility that opens a local TCP tunnel to a specific pod (or deployment) at a given local port:remote port. It does not create or modify any Service object; it only forwards traffic from localhost to the pod for as long as the command runs. Thus the deployment is not exposed as a stable network endpoint to other cluster components.

  • ✓

    Apply a Service YAML with selector matching the deployment's pod labels

    Why this is correct

    Applying a Service YAML with a selector that matches the labels on the deployment's pods creates a Service object that load-balances traffic to those pods. The selector must match the labels defined in the deployment's spec.selector and spec.template.metadata.labels. The Service's port and targetPort define how traffic reaches the containers. This is a declarative approach, suitable for GitOps, and ensures that the Service continuously tracks the pods created by the deployment.

  • ✗

    kubectl run web --image=nginx --port=80

    Why it's wrong here

    kubectl run creates a standalone Pod (or in newer versions a Deployment with a single replica) but does not create a Service. The --port flag only specifies the container port to expose in the container spec; it does not expose the pod to the cluster via a Service. To expose that workload you would still need a separate Service. Also, kubectl run is for ad-hoc pods, not a persistent Service exposure mechanism.

  • ✗

    kubectl create service clusterip web --tcp=80:80

    Why it's wrong here

    kubectl create service clusterip creates a Service of type ClusterIP but with no selector. Without a selector, the Service has no endpoints automatically populated, so it will not route traffic to the deployment's pods. You would have to manually add endpoints or edit the Service to include the deployment's pod selector; otherwise the Service has no backends.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.