KCNA Kubernetes Fundamentals Practice Question
A cluster administrator notices that a Deployment's pods are not receiving traffic as expected. The Service selector matches the pod labels. What is a possible cause?
⚠ Common exam trap
The exam often tests the distinction between liveness and readiness probes, trapping candidates who confuse a liveness probe failure (which restarts the pod) with a readiness probe failure (which removes the pod from the Service's endpoint list).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The pods have a failing readiness probe
A failing readiness probe removes the pod's endpoint from the Service's EndpointSlice, so the Service stops routing traffic to that pod even though the pod is running and its labels match the Service selector. This is the most direct reason why a Deployment's pods would not receive traffic despite correct label matching.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The pods have a liveness probe that fails
Why it's wrong here
A failing liveness probe restarts containers, but a restarting pod can still be a ready endpoint receiving traffic, so it does not by itself stop Service routing. It is tempting because probe failures are a common cause of pod instability, and they would be the answer if readiness, not liveness, were the probe in question.
- ✗
The Deployment replicas are set to zero
Why it's wrong here
If replicas are zero, no pods exist; but the scenario implies pods exist but don't receive traffic.
- ✓
The pods have a failing readiness probe
Why this is correct
A failing readiness probe removes the pod from the Service's endpoint list, so kube-proxy stops forwarding traffic to it even though the selector matches. This mechanism explains why matching pods receive no traffic, satisfying the stem's scenario of unexpected traffic loss.
- ✗
The Service type is NodePort
Why it's wrong here
NodePort merely exposes the Service on each node's IP at a static port; it does not stop selector-matched pods receiving ClusterIP traffic, so it cannot explain the symptom. It is tempting because NodePort is a real Service type used for external access, and would be chosen when clients outside the cluster must reach pods directly.
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.