CKAD Application Deployment Practice Question
You need to perform a canary deployment using a Service and two Deployments (stable and canary). Which TWO resources or configurations are typically used to route a percentage of traffic to the canary? (Select TWO)
⚠ Common exam trap
A common misconception in CKAD is that a single Service with multiple selectors can split traffic by percentage, when in fact Kubernetes Services only support label-based selection and round-robin load balancing without weighted routing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Service Mesh (e.g., Istio VirtualService)
Option A (Service Mesh, e.g., Istio VirtualService) is correct because a service mesh like Istio can split traffic between the stable and canary Deployments at the L7 level, using VirtualService/DestinationRule weights to send a precise percentage of requests to the canary subset. Option D (Ingress with canary annotation) is correct because ingress controllers such as NGINX Ingress support canary annotations (e.g., nginx.ingress.kubernetes.io/canary and canary-weight) to route a defined percentage of traffic to a canary backend Service. Option B is not valid because a Kubernetes Service has a single label selector and cannot natively split traffic by percentage across two Deployments. Option C is incorrect because NetworkPolicy only controls L3/L4 pod-level ingress/egress firewall rules, not HTTP traffic weighting. Option E is incorrect because a HorizontalPodAutoscaler only scales replica counts based on metrics and does not perform traffic routing or canary splitting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Service Mesh (e.g., Istio VirtualService)
Why this is correct
A service mesh such as Istio provides VirtualService and DestinationRule resources that split traffic between the stable and canary Deployments by weighted percentages, giving fine-grained, L7 control that a plain Kubernetes Service cannot achieve on its own.
- ✗
A single Service with multiple label selectors
Why it's wrong here
A Service has one selector; multiple label selectors cannot be combined to split traffic between stable and canary pods, so no percentage routing occurs. It tempts because selectors do bind pods to a Service, which is correct when all pods are identical and no traffic split is required.
- ✗
NetworkPolicy
Why it's wrong here
NetworkPolicy filters pod ingress and egress by IP, port and namespace; it cannot weight traffic between two Deployments behind one Service. It tempts because it governs pod-level connectivity, which is the right tool when the requirement is isolating or restricting traffic rather than splitting it proportionally.
- ✓
Ingress with canary annotation
Why this is correct
Ingress with canary annotations splits traffic by weighting rules at the ingress controller, satisfying the requirement to route a percentage of requests to the canary Deployment. Unlike a Service, which load-balances equally across all matching pods, ingress-level weighting lets you dial an exact proportion without scaling replica counts.
- ✗
HorizontalPodAutoscaler
Why it's wrong here
A HorizontalPodAutoscaler adjusts replica counts based on CPU or memory metrics, but it cannot split or weight traffic between two Deployments. It is tempting because it automates scaling, which might seem related to controlling canary capacity; however, it would be correct only for automatically scaling a single Deployment’s replicas in response to load, not for routing a percentage of requests to a canary.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.