CKAD Services and Networking Practice Question
You create a headless service with 'clusterIP: None' for a StatefulSet. How does a client discover the individual pod IPs?
⚠ Common exam trap
Test-takers frequently confuse headless services with regular ClusterIP services, assuming DNS returns a single virtual IP or that load balancing is still in effect, when in fact headless services expose individual pod IPs directly via DNS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS returns multiple A records for the service name, each pointing to a pod IP
A is correct because a headless service (clusterIP: None) does not provide a virtual IP or load balancing. Instead, DNS is configured to return multiple A records directly for the service name, each pointing to the IP address of a pod in the StatefulSet. This allows clients to discover and connect to individual pod IPs, which is essential for stateful applications where each pod has a unique identity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DNS returns multiple A records for the service name, each pointing to a pod IP
Why this is correct
A headless Service (clusterIP: None) removes the cluster-wide virtual IP, and CoreDNS creates an A record for every Ready pod that matches the Service's label selector. In a StatefulSet, each pod receives a stable hostname based on its ordinal, but the Service name itself returns a collection of A records containing the individual pod IPs. Clients can then connect directly to a chosen pod without any proxy involvement.
- ✗
The service returns the pod's hostname from the StatefulSet
Why it's wrong here
Kubernetes assigns each StatefulSet pod a stable hostname derived entirely from the StatefulSet name and pod ordinal, such as web-0 or db-1; this hostname is set by the StatefulSet controller, not by any Service. A headless Service only facilitates DNS-based endpoint discovery, so querying its DNS name yields IP addresses (or SRV records when a port is specified), not the pod's hostname field. The hostname is used internally for building per-pod DNS names like web-0.default.svc.cluster.local, but it is not a response returned by the Service itself.
- ✗
An Ingress controller must be configured to expose each pod
Why it's wrong here
Ingress is a Kubernetes API object that exposes HTTP/HTTPS routes from outside the cluster to a backing Service through an Ingress controller; it neither knows nor cares about individual pod IPs. For a headless Service, the intended use case is east-west discovery by applications inside the cluster, where DNS should return direct pod endpoints. There is no need for an Ingress controller unless you are exposing a web-facing application with host-based or path-based routing, and it would not change how the headless Service resolves to pod IPs.
- ✗
The service provides a virtual IP that load balances among pods
Why it's wrong here
A Service with clusterIP configured to a concrete IP address is backed by kube-proxy, which programs iptables or IPVS rules to load-balance every packet sent to that virtual IP across the ready endpoints. Selecting clusterIP: None disables this entire mechanism, so the Service never has a reachable VIP and no kube-proxy load-balancing rules are installed. Instead, the only artifact created is the DNS endpoint record set, meaning consumers are responsible for picking a specific pod IP from the returned A records.
Visual reference
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.