CKAD Services and Networking Practice Question
You have a Deployment named 'web' with label 'app: web'. You want to create a Service that exposes the Deployment on port 80 internally within the cluster. Which kubectl command achieves this?
⚠ Common exam trap
Candidates often confuse `kubectl expose` with `kubectl create service`, not realizing that `expose` automatically inherits the selector from the specified resource, while `create service` requires explicit selector configuration to bind to existing Pods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl expose deployment web --port=80
`kubectl expose deployment web --port=80` creates a ClusterIP Service that selects Pods based on the Deployment's label selector (app: web) and exposes port 80 internally within the cluster. This command directly maps the Deployment's Pods to a Service without requiring manual specification of the target port or protocol, defaulting to TCP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl create service clusterip web --tcp=80
Why it's wrong here
kubectl create service clusterip web --tcp=80 creates a Service object from scratch, but it does not automatically attach the label selector for the web Deployment's pods. Without a selector, the Service has no endpoints to route traffic to, so it remains unusable for reaching the Nginx replicas. This command is intended for defining headless or custom Services, not for wiring an existing workload.
- ✗
kubectl create deployment web --image=nginx --expose --port=80
Why it's wrong here
The kubectl create deployment subcommand does not support an --expose flag; this flag is a leftover from kubectl run and causes a 'unknown flag: --expose' error. As a result, the command exits without creating either a Deployment or a Service. The proper workflow is to create the Deployment first, then run kubectl expose deployment web --port=80 to generate the ClusterIP Service.
- ✗
kubectl expose pod web --port=80
Why it's wrong here
kubectl expose pod web --port=80 attempts to create a Service for a single Pod named web, but this Deployment's Pods have generated names like web-6b85b8f68d-xxxxx, so the lookup fails. Even if a Pod with that name existed, the Service would use the Pod's own IP address as the sole endpoint, bypassing the Deployment's ReplicaSet load balancing and leaving no resilience for scaling or restarts. The resource type must match the actual controller object.
- ✓
kubectl expose deployment web --port=80
Why this is correct
kubectl expose deployment web --port=80 creates a ClusterIP Service by reading the Deployment's label selector (app=web) and generating an Endpoints object that includes all matching Pods. Because the Deployment manages the Pods, the Service automatically follows rolling updates and scaling, providing a stable virtual IP for clients. This is the canonical command to expose a Deployment's port 80 without specifying a targetPort explicitly.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.