KCNA Kubernetes Fundamentals Practice Question
Which three of the following are valid methods to expose a Service to external traffic? (Select THREE)
⚠ Common exam trap
A common misconception is that ClusterIP can be used for external access because it has an IP address, but it is strictly internal unless combined with a proxy or port-forwarding mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ingress
Ingress (A) is a valid method because it exposes HTTP/HTTPS routes from outside the cluster to Services within the cluster using an Ingress resource backed by an Ingress controller. NodePort (B) is valid because it exposes a Service on each node's IP at a static port in the 30000–32767 range, making it reachable externally via <NodeIP>:<NodePort>. LoadBalancer (C) is valid because it provisions an external load balancer (e.g., via a cloud provider) that routes external traffic to the Service, typically building on NodePort and ClusterIP. ClusterIP (D) is not correct because it only exposes the Service on an internal cluster IP reachable solely within the cluster. ExternalName (E) is not correct because it merely maps a Service to an external DNS name via a CNAME record and does not expose or proxy external traffic to pods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ingress
Why this is correct
Ingress defines HTTP and HTTPS routing rules that map external hostnames and paths to internal Services, satisfying layer-7 external exposure through a single entry point. An ingress controller such as NGINX must be deployed to fulfil those rules.
- ✓
NodePort
Why this is correct
NodePort allocates a static port on every node, forwarding external traffic to the Service, satisfying exposure without cloud load-balancer integration. Clients reach any node IP on that port, and kube-proxy handles the forwarding to backend pods.
- ✓
LoadBalancer
Why this is correct
A LoadBalancer Service provisions an external load balancer through the cloud provider's controller, giving the Service a publicly reachable IP that routes inbound traffic to its endpoints. This satisfies the requirement to expose the Service to traffic originating outside the cluster.
- ✗
ClusterIP
Why it's wrong here
ClusterIP assigns a virtual IP reachable only from inside the cluster, so it cannot carry external traffic; external exposure needs NodePort, LoadBalancer or an Ingress. It tempts because every Service gets a ClusterIP by default, making it the most familiar type, yet that default is precisely what keeps it internal.
- ✗
ExternalName
Why it's wrong here
ExternalName returns a CNAME record pointing at an external DNS name, so it maps a Service to something outside the cluster rather than publishing cluster workloads externally. It tempts because the name suggests outside access, but the direction is reversed: it lets pods reach external services.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.