CKAD Services and Networking Practice Question
You have a Service named 'web' in namespace 'default'. Which DNS name resolves to the Service's ClusterIP?
⚠ Common exam trap
The CKAD exam often tests the exact DNS format for Services, and the trap here is that candidates may forget the `svc` subdomain or omit the namespace, leading them to choose options that look plausible but are missing a critical component.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
web.default.svc.cluster.local
In Kubernetes, the DNS name for a Service follows the pattern `<service>.<namespace>.svc.cluster.local`. For a Service named 'web' in the 'default' namespace, the correct FQDN is `web.default.svc.cluster.local`. This resolves to the Service's ClusterIP, allowing pods to reach the service via a stable DNS name.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
web.default.cluster.local
Why it's wrong here
This name omits the required 'svc' subdomain that is mandatory for all Kubernetes Service DNS records. The canonical FQDN pattern is <service-name>.<namespace>.svc.<cluster-domain>; without the 'svc' token, the name falls outside the DNS schema for Services and will not resolve to any ClusterIP or Endpoint. Therefore, even though it includes the correct service name and namespace, it is not a valid address for the 'web' Service.
- ✓
web.default.svc.cluster.local
Why this is correct
This is the fully qualified DNS name used by Kubernetes for any normal or headless Service in a given namespace, constructed as <service-name>.<namespace>.svc.<cluster-domain>. Here, 'web' is the Service name, 'default' is its namespace, and 'cluster.local' is the default cluster domain configured in CoreDNS. When a Pod connects to this name, the cluster's DNS resolver returns the Service's ClusterIP (or the pod IPs for a headless Service), making it the correct and standard address.
- ✗
web.svc.cluster.local
Why it's wrong here
This address is missing the namespace segment that is required to uniquely identify a Service across the cluster. The DNS schema always includes the namespace between the Service name and the 'svc' subdomain, so the correct form is web.default.svc.cluster.local, not web.svc.cluster.local. Without the namespace, the name is ambiguous and fails to resolve because CoreDNS only knows Services under their full namespace-qualified key, and Pods use namespace-scoped search domains that would not expand this malformed name properly.
- ✗
web.default.pod.cluster.local
Why it's wrong here
This name incorrectly uses the 'pod' subdomain, which is reserved for Pod DNS records, not Service records. In Kubernetes, a Pod's DNS name follows the pattern <hostname>.<subdomain>.<namespace>.pod.cluster.local, but Services are always placed under the 'svc' subdomain. Consequently, web.default.pod.cluster.local would never correspond to a Service A/AAAA record, and the 'web' Service would not be reachable at this name.
Visual reference
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.