CKAD Services and Networking Practice Question
Which TWO statements about Kubernetes Services are correct?
⚠ Common exam trap
Many exam-takers confuse 'accessible from outside' with 'accessible from within the cluster' for ClusterIP, or they mistakenly think a headless service still gets a ClusterIP, when in fact it explicitly does not.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Service provides a stable IP address and DNS name for a set of pods.
A Kubernetes Service provides a stable virtual IP address and a DNS name (via CoreDNS) that remains constant even as the underlying pods are created, destroyed, or scaled. This abstraction decouples clients from the ephemeral nature of pod IPs, ensuring reliable service discovery within the cluster.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A ClusterIP service is accessible from outside the cluster.
Why it's wrong here
ClusterIP is the default Service type and is only reachable from within the cluster network. It assigns a virtual IP that is routable only inside the cluster, typically via kube-proxy iptables or IPVS rules. External traffic must use NodePort, LoadBalancer, or an Ingress to reach the Service. So the statement is incorrect because ClusterIP is internal-only.
- ✓
A Service provides a stable IP address and DNS name for a set of pods.
Why this is correct
Kubernetes Services act as an abstraction layer that provides a stable virtual IP (ClusterIP) and a DNS name (e.g., my-service.my-namespace.svc.cluster.local) that remains unchanged even as pods are created, destroyed, or scaled. This decouples client access from the ephemeral pod IPs, enabling reliable service discovery and load balancing. The DNS name resolves to the ClusterIP, and kube-proxy forwards traffic to the backing pods.
- ✗
A Service can load balance traffic across multiple clusters.
Why it's wrong here
Kubernetes Services operate within a single cluster and are scoped to that cluster's network and endpoints. While multi-cluster solutions exist (e.g., Federation, Submariner, or an external load balancer), a Service itself does not span clusters. The Service's endpoints are derived from pod labels in the same cluster, so it cannot route traffic across cluster boundaries.
- ✓
A NodePort service exposes the service on a static port on each node's IP.
Why this is correct
A NodePort Service extends ClusterIP by allocating a port from a default range (30000-32767) and making the Service reachable at <NodeIP>:<NodePort> on every node in the cluster. Traffic sent to that static port is forwarded to the Service's ClusterIP and then load balanced to the pods. This allows external clients to access the Service via any node's IP, even if the node has no running pod for that Service.
- ✗
A headless service assigns a ClusterIP to the service.
Why it's wrong here
A headless Service is created by setting clusterIP: None in the Service spec, which tells Kubernetes not to allocate a virtual IP. Instead, the Service's DNS returns the actual pod IPs directly, enabling stateful applications to discover individual pods. Because no ClusterIP is assigned, kube-proxy does not create load-balancing rules for a headless Service.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.