CKAD Application Observability and Maintenance Practice Question
You are troubleshooting a service connectivity issue. You have a pod named 'client' and a service named 'server'. You want to check if the service's endpoints are populated. Which command should you run?
⚠ Common exam trap
A common mix-up: candidates confuse checking the service itself (which shows the selector) with checking the actual endpoints (which shows the resolved pod IPs), leading them to pick Option C when they need to verify if pods are actually backing the service.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl get endpoints server
`kubectl get endpoints server` directly retrieves the Endpoints object associated with the service named 'server'. Endpoints are automatically managed by Kubernetes and list the IP addresses and ports of pods that match the service's selector. If the endpoints list is empty, it indicates that no pods are matching the service's selector, which is a common cause of connectivity issues.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl describe pod client
Why it's wrong here
kubectl describe pod client inspects the source pod's metadata, status, and recent events, including its own IP and container states. It does not query the service's selector or the Endpoints object, so it cannot reveal which server pods are ready and receiving traffic. This command helps with issues like a client failing to start or an unresolved hostname, but it gives no visibility into whether the backing pods are registered as endpoints.
- ✗
kubectl get pods -l app=server
Why it's wrong here
kubectl get pods -l app=server lists all pods carrying that label regardless of readiness or lifecycle; a terminating, failed, or unscheduled pod may appear while contributing nothing to the load-balanced pool. The service's Endpoints resource is populated only with healthy pods that pass both the selector and the readiness probe. Without inspecting the Endpoints object, you cannot tell whether these labeled pods are actually wired into the service.
- ✗
kubectl get svc server
Why it's wrong here
kubectl get svc server displays the service's ClusterIP, port mapping, and selector, but the service object is declarative intent rather than runtime state. The control plane resolves that selector into concrete pod addresses and stores them in a separate Endpoints resource. Even if the service definitively selects pods, a missing or stale Endpoints entry is often the root failure, so this command alone cannot diagnose that layer.
- ✓
kubectl get endpoints server
Why this is correct
kubectl get endpoints server outputs the Endpoints resource for the named service, listing concrete IP addresses and ports of the ready pods behind it. An empty address list proves the service has no eligible endpoints, while populated entries let you verify a pod's IP matches what the client would reach. Because Endpoints are the runtime result of the service selector, this command directly exposes the data that load balancing uses.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.