KCNA NodePort Practice Question
Which TWO of the following are valid ways to expose a Service to external traffic?
⚠ Common exam trap
A common pitfall is assuming ExternalName or Headless Services provide external exposure. ExternalName only provides an internal DNS alias, while Headless is for internal pod discovery. Only NodePort and LoadBalancer directly expose the Service externally.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
LoadBalancer
NodePort (D) is correct because it exposes a Service on each cluster node's IP at a static port in the 30000–32767 range, allowing external clients to reach the Service via <NodeIP>:<NodePort>. LoadBalancer (C) is correct because it builds on NodePort and provisions an external load balancer (e.g., via a cloud provider) that routes external traffic to the Service's endpoints. ExternalName (A) is not a way to expose a Service to external traffic; it simply returns a CNAME DNS record pointing to an external hostname without proxying traffic. Headless (B) sets clusterIP: None and returns pod IPs directly via DNS, which is used for direct pod discovery, not external exposure. ClusterIP (E) is the default internal-only Service type, reachable only from within the cluster, so it does not expose the Service externally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ExternalName
Why it's wrong here
ExternalName maps a Service to an external DNS name via a CNAME record; it exposes no cluster workload to outside clients. It is tempting because the name suggests external access, but it only lets pods resolve an external hostname — inbound exposure needs NodePort or LoadBalancer.
- ✗
Headless
Why it's wrong here
A headless Service sets clusterIP to None, returning pod IPs directly via DNS for stateful discovery; it provides no external exposure. It is tempting because it is a distinct Service configuration, but external traffic requires NodePort, LoadBalancer or an Ingress, not a headless definition.
- ✓
LoadBalancer
Why this is correct
A LoadBalancer Service provisions an external cloud load balancer that routes inbound traffic to the backing pods. This exposes the Service beyond the cluster, unlike ClusterIP, which remains reachable only internally within the cluster network.
- ✓
NodePort
Why this is correct
NodePort allocates a static port on every node's IP, forwarding external traffic to the Service's cluster IP and pods. This provides external reachability without a cloud load balancer, directly satisfying the stem's requirement for exposing a Service to external traffic.
- ✗
ClusterIP
Why it's wrong here
ClusterIP assigns a virtual IP reachable only from within the cluster, so external clients cannot connect to it. It is tempting because it is the default Service type and underpins NodePort and LoadBalancer, but those types add external reachability; ClusterIP alone provides internal-only access.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.