Courseiva
Container Orchestration →hardMultiple Choice

KCNA Container Orchestration Practice Question

A microservices application has multiple services that need to discover each other by name. Which Kubernetes object provides built-in service discovery via DNS?

⚠ Common exam trap

Many exam-takers confuse Ingress (external routing) with internal DNS-based service discovery, or assume that Namespaces themselves provide DNS resolution, when in fact it is the Service object that triggers DNS record creation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Service

A Kubernetes Service object provides built-in service discovery via DNS. When a Service is created, the cluster's DNS (typically CoreDNS) automatically assigns it a DNS name in the format `<service>.<namespace>.svc.cluster.local`, allowing other microservices to resolve the Service by name without hardcoding IP addresses or using external service registries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ingress

    Why it's wrong here

    Ingress routes external HTTP and HTTPS traffic to Services based on host and path rules; it does not create the cluster DNS records that resolve a Service name to its ClusterIP. It is tempting because Ingress does reference Services by name. Ingress would be correct for publishing an application externally, not for internal service-to-service discovery.

  • ✗

    Namespace

    Why it's wrong here

    Namespaces partition cluster objects for isolation, quotas and RBAC scoping; they do not publish DNS names for Services. It is tempting because DNS names include the namespace segment, implying namespaces provide discovery. A namespace would be correct for separating teams or environments, not for resolving a Service to its ClusterIP.

  • ✗

    ConfigMap

    Why it's wrong here

    ConfigMaps inject non-confidential configuration data as environment variables or mounted files; they hold no network identity and register no DNS records. It is tempting because service endpoints are sometimes templated into configuration. A ConfigMap would be correct for supplying application settings, not for resolving service names to addresses.

  • ✓

    Service

    Why this is correct

    A Service assigns a stable DNS name and virtual IP to a set of pods, letting microservices resolve each other by name regardless of pod churn. It provides the built-in service discovery the scenario requires.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Go deeper

Related to this question

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.