CKAD Services and Networking Practice Question
You create a Service with `kubectl expose deployment web --port=80 --target-port=8080`. What type of Service is created by default?
⚠ Common exam trap
Test-takers frequently assume `kubectl expose` creates a NodePort or LoadBalancer Service by default because they associate 'expose' with external access, but Kubernetes defaults to ClusterIP for internal-only exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ClusterIP
When you run `kubectl expose deployment web --port=80 --target-port=8080` without specifying the `--type` flag, Kubernetes defaults to creating a Service of type ClusterIP. This is because ClusterIP is the default Service type in Kubernetes, providing internal cluster-only access to the pods via a stable virtual IP address.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ClusterIP
Why this is correct
ClusterIP is the default Service type because the Service API's `type` field defaults to `ClusterIP` when omitted, so `kubectl expose deployment web p` creates a stable virtual IP reachable only inside the cluster. It assigns an internal cluster IP and load balances TCP/UDP across the selected pod endpoints through kube-proxy's iptables or IPVS rules, with no external exposure.
- ✗
LoadBalancer
Why it's wrong here
LoadBalancer is incorrect here because it is not the default; you would need to pass `--type=LoadBalancer` to `kubectl expose` to request cloud-provider integration. That type provisions an external load balancer (e.g., an AWS ELB or GCP LB) and assigns a public/external IP, whereas the plain command produced a ClusterIP service that is only accessible from inside the cluster network.
- ✗
NodePort
Why it's wrong here
NodePort is incorrect because it requires explicitly setting `--type=NodePort`; the default `kubectl expose` command does not open any node-level port. A NodePort service maps a fixed high port (30000–32767) on every node's IP and forwards traffic to the ClusterIP, so if this were the default, every Kubernetes node would immediately become externally reachable on that port—clearly not the behavior of the plain command.
- ✗
ExternalName
Why it's wrong here
ExternalName is incorrect because it must be requested with `--type=ExternalName` and is fundamentally different from a standard Service: it has no pod selectors and no ClusterIP, instead returning a CNAME alias to an external DNS name. The plain `kubectl expose deployment web p` targets an existing Deployment's pods, whereas an ExternalName service would need an explicit `externalName` value and does not load-balance workloads.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.