Courseiva
Services and Networking →mediumMultiple Select

CKAD Services and Networking Practice Question

Which TWO of the following are valid ways to expose a service externally on a Kubernetes cluster? (Select 2)

⚠ Common exam trap

It's easy for candidates to confuse `kubectl port-forward` (a debugging tool) with a persistent service exposure method, or think ExternalName provides external access when it only creates a DNS alias within the cluster.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NodePort

A NodePort service exposes the service on a static port on each node's IP address, making it accessible from outside the cluster via `<NodeIP>:<NodePort>`. This is a valid method for external exposure, as it opens a port in the node's firewall and routes traffic to the service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    NodePort

    Why this is correct

    A NodePort service exposes the application by opening a static TCP/UDP port in the default range 30000-32767 on every Kubernetes node. Any client can reach the service by sending requests to `nodeIP:nodePort`, and traffic is automatically routed to the backend pods. It is a valid, production-grade exposure method, though it provides no advanced load balancing and leaves the node IPs publicly reachable.

  • ✗

    kubectl port-forward

    Why it's wrong here

    kubectl port-forward is not a valid production service exposure technique because it creates a user-initiated, ephemeral tunnel from a local machine to a specific pod or service via the Kubernetes API server. The tunnel is only active while the command is running and is typically used for debugging, inspecting APIs, or accessing internal dashboards. It cannot serve persistent external traffic and does not integrate with cluster networking, so it is unsuitable for exposing a service to end users.

  • ✗

    ExternalName

    Why it's wrong here

    An ExternalName Service does not expose anything to external traffic; instead, it maps a Service name to an external DNS CNAME record, causing cluster DNS to return that external domain rather than forwarding requests to pods. It is used to provide a stable internal DNS alias for services hosted outside the cluster, such as a legacy database or a SaaS API. Because it only alters DNS resolution and has no selectors or ports, it cannot receive and route external client requests.

  • ✓

    LoadBalancer

    Why this is correct

    A LoadBalancer Service is a valid way to expose an application externally, as it instructs the cloud provider to provision a managed load balancer (e.g., AWS ELB, GCP LB) and assigns it a public, routable IP address. The load balancer forwards traffic to the NodePorts opened on each node, which then route to the backend pods. This is the standard approach for internet-facing services in cloud environments, because it provides automatic health checks, traffic distribution, and a single stable ingress point.

  • ✗

    ClusterIP

    Why it's wrong here

    ClusterIP is the default Service type, and it is not valid for external exposure because the virtual IP it creates exists only inside the cluster's private network space. It is reachable by pods, kube-proxy, and other internal components, but the cluster's network is not configured to route external traffic to that IP. External access would require an additional mechanism such as an Ingress, a NodePort, a LoadBalancer, or a port-forward, which contradicts relying on ClusterIP alone for exposure.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.