CKAD Services and Networking Practice Question
You run 'kubectl port-forward pod/my-pod 8080:80'. What does this command do?
⚠ Common exam trap
Many exam-takers confuse `kubectl port-forward` with `kubectl expose` or a NodePort Service, thinking it makes the pod accessible externally, when in fact it only forwards traffic from a local port to the pod on the client machine.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Forwards local port 8080 to port 80 on the pod
`kubectl port-forward pod/my-pod 8080:80` creates a tunnel from localhost:8080 on your client machine to port 80 on the specified pod. This command does not expose the pod to the network; it only provides a direct, temporary connection for debugging or accessing a specific pod without a Service.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Exposes the pod on port 8080 on each node's IP
Why it's wrong here
This description confuses a client-side port-forward operation with a server-side NodePort or LoadBalancer Service. kubectl port-forward never binds a port on any node's IP address; it creates a local TCP listener on the machine where kubectl runs, by default on localhost, and tunnels traffic through the Kubernetes API server to the specified pod. The pod is not exposed to external network traffic or to other nodes in the cluster.
- ✓
Forwards local port 8080 to port 80 on the pod
Why this is correct
This is precisely what the command does: it opens a local TCP listener on port 8080 (typically on 127.0.0.1) and forwards every connection to port 80 on the pod named mypod. The kubectl binary acts as a client that establishes a connection to the Kubernetes API server, which then proxies a bidirectional stream to the requested port on the pod. This is a convenient way to reach a pod that is not exposed by a Service, without altering the cluster state.
- ✗
Forwards local port 8080 to port 80 on the Service
Why it's wrong here
The command explicitly targets a pod resource, not a Service — 'pod mypod' tells kubectl exactly which pod to use. The tunnel created by port-forward does not go through a Service object or its ClusterIP; it connects directly to the pod's IP and port. Even when you tell kubectl to forward to a Service, kubectl resolves the Service to an arbitrary backing pod, so the connection is still to an individual pod, not to the Service abstraction.
- ✗
Creates a Service that maps port 8080 to port 80 on the pod
Why it's wrong here
kubectl port-forward does not create any Kubernetes API object; it is purely a local, client-side process. After the command runs, no Service exists and no cluster resources are changed — the only effect is a temporary listener on the local machine that drops the tunnel once kubectl is killed. A Service that maps ports would require creating a Service manifest or running kubectl expose, which is a separate, persistent, server-side operation.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.