CKAD Services and Networking Practice Question
You need to debug a Service that is not routing traffic to its endpoints. Which command shows the current endpoints of a Service?
⚠ Common exam trap
It's easy for candidates to assume `kubectl describe service` or `kubectl get svc -o wide` shows the full endpoint list, but these commands only provide a summary or count, not the actual IP:port pairs, leading to incomplete debugging.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl get endpoints my-service
`kubectl get endpoints my-service` directly retrieves the Endpoints object associated with the Service, which lists the IP addresses and ports of the Pods that are currently receiving traffic. This is the most precise way to verify whether the Service has any active endpoints, as the Endpoints object is updated by the kube-controller-manager based on Pod readiness and label selectors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl describe service my-service
Why it's wrong here
kubectl describe service my-service provides high-level Service metadata such as the label selector, ports, and recent events, but it does not enumerate the resolved backend IPs. While it can help you confirm the selector and port configuration, it gives no direct insight into whether any pods are currently registered as endpoints, so it fails to pinpoint the exact routing failure.
- ✗
kubectl get svc my-service -o wide
Why it's wrong here
kubectl get svc my-service -o wide extends the basic Service listing with additional fields like ClusterIP, ExternalIP, NodePort, and type, but it still does not expose the individual pod IPs behind the Service. This view is useful for verifying service-level networking configuration, yet it remains blind to the endpoint membership that actually determines whether traffic can flow.
- ✗
kubectl get pods -l app=my-app
Why it's wrong here
kubectl get pods -l app=my-app only lists pods that match the given label, which may not match the Service's actual selector. Even if they do match, running pods are not automatically endpoints—they must also pass their readiness probes; otherwise they remain in the Pod list but are excluded from the Endpoints object, leaving the Service with no routable targets.
- ✓
kubectl get endpoints my-service
Why this is correct
kubectl get endpoints my-service is the correct debugging step because it queries the Endpoints object associated with the Service, which lists the actual IP:port pairs of healthy, ready pods that kube-proxy will forward traffic to. If this listing is empty, you immediately know the Service has no backends and can then investigate the selector match or readiness of matching pods.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.