Courseiva
Services and Networking →mediumMultiple Choice

CKAD Services and Networking Practice Question

You have an Ingress that should route requests to 'api.example.com' to a service named 'api-svc' on port 80, and requests to 'www.example.com' to 'web-svc' on port 80. Which host-based routing rule is correct?

⚠ Common exam trap

A common mix-up: candidates confuse the placement of `host` as a field inside `paths` (Option A) or omit the `http:` wrapper (Option C), because they think host-based routing is defined per path rather than per rule, or they recall the deprecated API syntax (Option D) from older Kubernetes versions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

spec: rules: - host: api.example.com http: paths: - backend: service: name: api-svc port: number: 80 - host: www.example.com http: paths: - backend: service: name: web-svc port: number: 80

It follows the Kubernetes Ingress v1 API specification: each rule in `spec.rules` is an object with a `host` field and an `http` field, and within `http`, a `paths` array containing backend references. This structure correctly routes requests for `api.example.com` to `api-svc:80` and `www.example.com` to `web-svc:80`.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    spec: rules: - http: paths: - host: api.example.com backend: service: name: api-svc port: number: 80 - host: www.example.com backend: service: name: web-svc port: number: 80

    Why it's wrong here

    The `host` field is incorrectly nested inside a `path` entry. In the Ingress `rules` schema, `host` is a property of each rule, not of each path. Each path must reside under an `http` block within a rule, and multiple paths can share one rule's `http` block. As written, this manifest places `host` at the path level, which doesn't match the expected structure and would cause the Ingress controller to reject or misroute traffic.

  • ✓

    spec: rules: - host: api.example.com http: paths: - backend: service: name: api-svc port: number: 80 - host: www.example.com http: paths: - backend: service: name: web-svc port: number: 80

    Why this is correct

    This correctly defines two separate Ingress rules, each with its own `host` at the rule level. Each rule then has an `http` block containing a `paths` array, and each path designates a backend using the current `service.name` and `service.port.number` fields. This enables host-based routing: requests for api.example.com go to api-svc, while www.example.com requests go to web-svc.

  • ✗

    spec: rules: - host: api.example.com - backend: service: name: api-svc port: number: 80 - host: www.example.com - backend: service: name: web-svc port: number: 80

    Why it's wrong here

    This manifest has a structural YAML problem: a `-` list item is introduced immediately after the `host` field, but the rule object expects an `http` key, not a sub-list. A rule in the `rules` array must be a mapping with optional `host` and an `http` key; placing a `- backend:` there creates a sequence where a mapping is required, so the Ingress resource cannot be parsed correctly.

  • ✗

    spec: rules: - host: api.example.com http: paths: - backend: serviceName: api-svc servicePort: 80 - host: www.example.com http: paths: - backend: serviceName: web-svc servicePort: 80

    Why it's wrong here

    This option uses `serviceName` and `servicePort`, which are legacy fields from the v1beta1 Ingress API. The current networking.k8s.io/v1 schema requires `service.name` and `service.port.number` (or `service.port.name`) inside the `backend`. Even though the high-level rule structure is correct, the deprecated field names render the manifest invalid under the current API version.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.