CKAD Services and Networking Practice Question
You need to temporarily access a pod's HTTP endpoint on port 8080 from your local machine. Which command should you use?
⚠ Common exam trap
Watch out — candidates often confuse `kubectl port-forward` with `kubectl proxy` or `kubectl exec`, thinking that running a command inside the pod or proxying the API server will expose the pod's application port, when in fact only port-forward creates a direct local-to-pod TCP tunnel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl port-forward pod/my-pod 8080:8080
`kubectl port-forward` creates a direct tunnel from a local port to a pod's port, allowing you to access the pod's HTTP endpoint at `localhost:8080` from your local machine. This is the standard method for temporarily exposing a pod's network endpoint without creating a Service or modifying cluster networking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl exec -it pod/my-pod -- curl http://localhost:8080
Why it's wrong here
kubectl exec -it pod/my-pod -- curl http://localhost:8080 runs the curl command inside the pod's container, not on your local machine. While it can reach the pod's HTTP endpoint from within the pod's own network namespace, it does not expose that endpoint to your local browser or client, and it also depends on curl being installed in the container image.
- ✗
kubectl proxy --port=8080
Why it's wrong here
kubectl proxy --port=8080 starts a local proxy that forwards traffic to the Kubernetes API server, not to a specific pod's HTTP endpoint. It can indirectly reach pod ports only by crafting URL paths like /api/v1/namespaces/default/pods/my-pod:8080/proxy/, but it does not simply make localhost:8080 map to your pod's 8080, so it is not the intended way to access the endpoint.
- ✗
kubectl attach pod/my-pod
Why it's wrong here
kubectl attach pod/my-pod attaches your terminal to the main process running in the pod's container, streaming its stdin/stdout/stderr. It is used for interactive debugging or observing output, not for forwarding network traffic, so it cannot expose the pod's HTTP port for local connections.
- ✓
kubectl port-forward pod/my-pod 8080:8080
Why this is correct
kubectl port-forward pod/my-pod 8080:8080 correctly forwards localhost:8080 on your workstation to port 8080 on the pod. It establishes a tunnel through the Kubernetes API server, letting you access the pod's HTTP endpoint as if it were running locally, without requiring a Service or exposing the pod externally.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.