KCNA Kubernetes Fundamentals Practice Question
Which THREE of the following are valid ways to expose a Service to external traffic? (Select exactly three.)
⚠ Common exam trap
Candidates often mistakenly think ExternalName is an external exposure method, but it only creates a DNS alias within the cluster and does not route external traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ingress
Ingress (A) is correct because an Ingress resource defines HTTP/HTTPS routing rules that expose Services externally through an Ingress controller acting as a layer-7 entry point. NodePort (D) is correct because it allocates a static port on every node's IP (default range 30000-32767), making the Service reachable from outside the cluster via <NodeIP>:<NodePort>. LoadBalancer (E) is correct because it provisions an external load balancer (e.g., via a cloud provider) that distributes traffic to the Service from outside the cluster. ExternalName (B) is not a way to expose a Service; it merely maps a Service to an external DNS name via a CNAME record without proxying traffic. ClusterIP (C) is not externally accessible since it only assigns an internal virtual IP reachable within the cluster.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ingress
Why this is correct
Ingress satisfies external exposure by routing HTTP and HTTPS traffic from outside the cluster to Services, using host- or path-based rules defined in an Ingress resource and implemented by an ingress controller. It provides layer 7 load balancing, terminating external requests and forwarding them internally, which meets the requirement for exposing Services to external traffic.
- ✗
ExternalName
Why it's wrong here
ExternalName returns a CNAME record pointing to an external DNS name, creating no proxy or cluster IP, so it does not expose pods to external traffic. It is tempting because it references external services, and would be correct for aliasing an in-cluster name to an external database.
- ✗
ClusterIP
Why it's wrong here
ClusterIP assigns a virtual IP reachable only from inside the cluster, so external clients cannot route to it. It is tempting because it is the default Service type and is correct for internal pod-to-pod communication, but exposure to external traffic requires NodePort or LoadBalancer instead.
- ✓
NodePort
Why this is correct
NodePort opens a static port on every node's IP, forwarding external traffic to the Service's cluster IP. It satisfies the requirement for exposing a Service externally without a cloud load balancer, making it one of the three valid exposure methods.
- ✓
LoadBalancer
Why this is correct
LoadBalancer Services request a cloud provider's load balancer, provisioning an external IP that routes traffic directly to the Service's pods. This satisfies the stem's requirement for exposing a Service to external traffic, unlike ClusterIP, which stays internal-only. It is one of Kubernetes' three native external exposure mechanisms alongside NodePort and Ingress.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.