KCNA Kubernetes Fundamentals Practice Question
A DevOps engineer needs to expose a set of pods running an HTTP API to external clients. The pods are stateless and should be load-balanced. Which Kubernetes resource should they use?
⚠ Common exam trap
Many exam-takers confuse 'exposing to external clients' with internal-only services, leading them to pick ClusterIP (C) or assume Ingress (B) can work without a Service, while the question explicitly requires load balancing for stateless pods, making LoadBalancer the direct and correct answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Service of type LoadBalancer
A Service of type LoadBalancer is the correct choice because it provisions an external load balancer (e.g., an AWS ELB or Azure LB) that distributes incoming traffic across the pods, exposing the stateless HTTP API to external clients. This resource automatically assigns a public IP and handles load balancing without requiring manual proxy configuration, making it ideal for external access to stateless workloads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
StatefulSet with a headless Service
Why it's wrong here
A StatefulSet with a headless Service gives each pod a stable network identity and no load balancing, which suits stateful databases, not stateless HTTP APIs. It is tempting when stable DNS names and persistent storage are required, but this scenario needs external load-balanced access to interchangeable pods.
- ✗
Ingress resource without a Service
Why it's wrong here
An Ingress resource routes external HTTP traffic to a Service, so without a backing Service it has no endpoints to forward requests to. It is tempting because Ingress does expose HTTP APIs externally, but that applies once a ClusterIP or NodePort Service already selects the pods.
- ✗
Service of type ClusterIP
Why it's wrong here
ClusterIP provides only an internal virtual IP reachable within the cluster, so external clients cannot connect. It is tempting because it is the default Service type for pod-to-pod and internal load balancing, and would be correct for exposing the API only to other in-cluster workloads.
- ✓
Service of type LoadBalancer
Why this is correct
A Service of type LoadBalancer provisions an external load balancer that distributes traffic across the stateless pod endpoints, exposing the HTTP API to external clients. ClusterIP is internal only, and NodePort lacks integrated load balancing.
Go deeper
Related to this question
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.