KCNA Kubernetes Fundamentals Practice Question
A team runs a stateless web application in Kubernetes. They have a Deployment named 'web-app' with 5 replicas. They want to ensure that a Service named 'web-svc' distributes traffic evenly to all healthy pods. Which type of Service should they use?
⚠ Common exam trap
Test-takers frequently think NodePort or Headless Service are needed for load balancing, but the question specifically asks for internal traffic distribution to pods, and ClusterIP is the default and correct Service type for that purpose, while Headless Service actually removes load balancing entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ClusterIP
A ClusterIP Service is the correct choice because it provides a stable virtual IP address and round-robin load balancing across healthy pods in the Deployment. By default, kube-proxy uses iptables or IPVS rules to distribute traffic evenly to all ready pod endpoints, ensuring stateless web application requests are balanced without requiring external exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ClusterIP
Why this is correct
ClusterIP provides a stable virtual IP that load-balances across all pods matching the Service's selector, so traffic spreads evenly across the five healthy replicas. It satisfies the internal distribution requirement without exposing the Service externally, which suits a stateless web application accessed by other cluster workloads.
- ✗
Headless Service
Why it's wrong here
A Headless Service returns individual pod IPs via DNS rather than a single virtual IP, so no load balancing across the five replicas occurs. It is tempting because headless Services genuinely suit StatefulSets needing stable per-pod DNS identities, but this stateless web tier requires ClusterIP distribution across all healthy endpoints.
- ✗
ExternalName Service
Why it's wrong here
ExternalName maps the Service to an external DNS name via a CNAME record, providing no selector, endpoints, or traffic distribution to the five pods. It is tempting because ExternalName legitimately exposes external dependencies, such as a managed database, to in-cluster clients, but it cannot front internal replica sets.
- ✗
NodePort
Why it's wrong here
NodePort exposes the Service on each node's IP at a static port, so traffic reaches pods only via node addresses and kube-proxy rules, not through a stable cluster-wide virtual IP. ClusterIP is the correct type for even distribution to healthy pods. NodePort suits external access to a single service.
Go deeper
Related to this question
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.