CKAD Application Observability and Maintenance Practice Question
You need to configure a liveness probe that checks if the container port 8080 is open. Which probe type should you use?
⚠ Common exam trap
Watch out — candidates often choose httpGet because they assume a web server on port 8080, but the question explicitly asks only to check if the port is open, not to validate an HTTP response, making tcpSocket the precise and minimal probe type.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
tcpSocket
A tcpSocket probe is the correct choice when you need to verify that a container is listening on a specific TCP port, such as port 8080. It works by attempting to open a TCP connection to the specified port; if the connection succeeds, the probe is considered successful. This is ideal for checking basic network-level readiness or liveness without requiring an HTTP endpoint or a custom command.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
tcpSocket
Why this is correct
The tcpSocket probe instructs the kubelet to attempt a raw TCP connection to the specified port (e.g., `:8080`) and marks the container healthy if the three-way handshake completes successfully. It does not interpret any application-level response, so it is ideal for verifying that a listener is active on the port without requiring an HTTP or gRPC endpoint. This matches the requirement to check if the port is open and is therefore the correct choice.
- ✗
grpc
Why it's wrong here
The grpc probe relies on the gRPC health checking protocol, calling the standard `grpc.health.v1.Health/Check` method with a service name. Your application must therefore implement a gRPC health service and respond with `SERVING`; a plain TCP server or non-gRPC application cannot satisfy this probe. Because the question asks for a connectivity check on a TCP port, not a gRPC health endpoint, this option is incorrect.
- ✗
exec
Why it's wrong here
An exec probe runs a command such as `cat /tmp/healthy` inside the container and uses the exit status as the health signal, which verifies only container-internal state. It does not test whether the port is reachable from outside the container, nor whether the network stack and service listener are actually prepared to accept connections. Since the liveness check is intended to validate a listening port, this approach is unsuitable.
- ✗
httpGet
Why it's wrong here
The httpGet probe performs an HTTP GET request to a given path and port, declaring success for any status code in the 200–399 range based on the `successThreshold` configuration. This requires an HTTP server inside the container, and a service that simply accepts TCP connections without speaking HTTP will cause the probe to time out or fail. It thus adds an application-layer dependency that is unnecessary and incorrect for checking only that a TCP port is open.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.