Courseiva
Services and Networking →mediumMultiple Choice

CKAD Services and Networking Practice Question

You run 'kubectl port-forward pod/my-pod 8080:80'. What does this command do?

⚠ Common exam trap

Many exam-takers confuse `kubectl port-forward` with `kubectl expose` or a NodePort Service, thinking it makes the pod accessible externally, when in fact it only forwards traffic from a local port to the pod on the client machine.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Forwards local port 8080 to port 80 on the pod

`kubectl port-forward pod/my-pod 8080:80` creates a tunnel from localhost:8080 on your client machine to port 80 on the specified pod. This command does not expose the pod to the network; it only provides a direct, temporary connection for debugging or accessing a specific pod without a Service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Exposes the pod on port 8080 on each node's IP

    Why it's wrong here

    This description confuses a client-side port-forward operation with a server-side NodePort or LoadBalancer Service. kubectl port-forward never binds a port on any node's IP address; it creates a local TCP listener on the machine where kubectl runs, by default on localhost, and tunnels traffic through the Kubernetes API server to the specified pod. The pod is not exposed to external network traffic or to other nodes in the cluster.

  • ✓

    Forwards local port 8080 to port 80 on the pod

    Why this is correct

    This is precisely what the command does: it opens a local TCP listener on port 8080 (typically on 127.0.0.1) and forwards every connection to port 80 on the pod named mypod. The kubectl binary acts as a client that establishes a connection to the Kubernetes API server, which then proxies a bidirectional stream to the requested port on the pod. This is a convenient way to reach a pod that is not exposed by a Service, without altering the cluster state.

  • ✗

    Forwards local port 8080 to port 80 on the Service

    Why it's wrong here

    The command explicitly targets a pod resource, not a Service — 'pod mypod' tells kubectl exactly which pod to use. The tunnel created by port-forward does not go through a Service object or its ClusterIP; it connects directly to the pod's IP and port. Even when you tell kubectl to forward to a Service, kubectl resolves the Service to an arbitrary backing pod, so the connection is still to an individual pod, not to the Service abstraction.

  • ✗

    Creates a Service that maps port 8080 to port 80 on the pod

    Why it's wrong here

    kubectl port-forward does not create any Kubernetes API object; it is purely a local, client-side process. After the command runs, no Service exists and no cluster resources are changed — the only effect is a temporary listener on the local machine that drops the tunnel once kubectl is killed. A Service that maps ports would require creating a Service manifest or running kubectl expose, which is a separate, persistent, server-side operation.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.