Courseiva
Kubernetes Fundamentals →easyMultiple Choice

KCNA Kubernetes Fundamentals Practice Question

A DevOps engineer needs to expose a set of pods running an HTTP API to external clients. The pods are stateless and should be load-balanced. Which Kubernetes resource should they use?

⚠ Common exam trap

Many exam-takers confuse 'exposing to external clients' with internal-only services, leading them to pick ClusterIP (C) or assume Ingress (B) can work without a Service, while the question explicitly requires load balancing for stateless pods, making LoadBalancer the direct and correct answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Service of type LoadBalancer

A Service of type LoadBalancer is the correct choice because it provisions an external load balancer (e.g., an AWS ELB or Azure LB) that distributes incoming traffic across the pods, exposing the stateless HTTP API to external clients. This resource automatically assigns a public IP and handles load balancing without requiring manual proxy configuration, making it ideal for external access to stateless workloads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    StatefulSet with a headless Service

    Why it's wrong here

    A StatefulSet with a headless Service gives each pod a stable network identity and no load balancing, which suits stateful databases, not stateless HTTP APIs. It is tempting when stable DNS names and persistent storage are required, but this scenario needs external load-balanced access to interchangeable pods.

  • ✗

    Ingress resource without a Service

    Why it's wrong here

    An Ingress resource routes external HTTP traffic to a Service, so without a backing Service it has no endpoints to forward requests to. It is tempting because Ingress does expose HTTP APIs externally, but that applies once a ClusterIP or NodePort Service already selects the pods.

  • ✗

    Service of type ClusterIP

    Why it's wrong here

    ClusterIP provides only an internal virtual IP reachable within the cluster, so external clients cannot connect. It is tempting because it is the default Service type for pod-to-pod and internal load balancing, and would be correct for exposing the API only to other in-cluster workloads.

  • ✓

    Service of type LoadBalancer

    Why this is correct

    A Service of type LoadBalancer provisions an external load balancer that distributes traffic across the stateless pod endpoints, exposing the HTTP API to external clients. ClusterIP is internal only, and NodePort lacks integrated load balancing.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.