Courseiva
Services and Networking →mediumMultiple Choice

CKAD Services and Networking Practice Question

You need to debug a Service that is not routing traffic to its endpoints. Which command shows the current endpoints of a Service?

⚠ Common exam trap

It's easy for candidates to assume `kubectl describe service` or `kubectl get svc -o wide` shows the full endpoint list, but these commands only provide a summary or count, not the actual IP:port pairs, leading to incomplete debugging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl get endpoints my-service

`kubectl get endpoints my-service` directly retrieves the Endpoints object associated with the Service, which lists the IP addresses and ports of the Pods that are currently receiving traffic. This is the most precise way to verify whether the Service has any active endpoints, as the Endpoints object is updated by the kube-controller-manager based on Pod readiness and label selectors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl describe service my-service

    Why it's wrong here

    kubectl describe service my-service provides high-level Service metadata such as the label selector, ports, and recent events, but it does not enumerate the resolved backend IPs. While it can help you confirm the selector and port configuration, it gives no direct insight into whether any pods are currently registered as endpoints, so it fails to pinpoint the exact routing failure.

  • ✗

    kubectl get svc my-service -o wide

    Why it's wrong here

    kubectl get svc my-service -o wide extends the basic Service listing with additional fields like ClusterIP, ExternalIP, NodePort, and type, but it still does not expose the individual pod IPs behind the Service. This view is useful for verifying service-level networking configuration, yet it remains blind to the endpoint membership that actually determines whether traffic can flow.

  • ✗

    kubectl get pods -l app=my-app

    Why it's wrong here

    kubectl get pods -l app=my-app only lists pods that match the given label, which may not match the Service's actual selector. Even if they do match, running pods are not automatically endpoints—they must also pass their readiness probes; otherwise they remain in the Pod list but are excluded from the Endpoints object, leaving the Service with no routable targets.

  • ✓

    kubectl get endpoints my-service

    Why this is correct

    kubectl get endpoints my-service is the correct debugging step because it queries the Endpoints object associated with the Service, which lists the actual IP:port pairs of healthy, ready pods that kube-proxy will forward traffic to. If this listing is empty, you immediately know the Service has no backends and can then investigate the selector match or readiness of matching pods.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.