Courseiva
Container Orchestration →hardMultiple Select

KCNA Container Orchestration Practice Question

Which TWO of the following are true about service discovery in Kubernetes? (Choose 2)

⚠ Common exam trap

The trap is confusing Ingress (external HTTP routing) with internal service discovery, and misremembering headless Services as providing a virtual IP when they actually return pod IPs directly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Environment variables are injected into pods for each Service

Option C is correct because Kubernetes injects environment variables (such as <SERVICE_NAME>_SERVICE_HOST and <SERVICE_NAME>_SERVICE_PORT) into every pod for each Service that exists at the time the pod is created, providing one built-in discovery mechanism. Option D is correct because CoreDNS (the cluster DNS add-on) assigns each Service a fully qualified domain name of the form <service>.<namespace>.svc.cluster.local, which pods resolve to reach the Service's ClusterIP. Option A is not correct because Ingress resources handle external HTTP/HTTPS routing into the cluster, not internal service discovery. Option B is not correct because Service discovery works cluster-wide across all nodes, not just for pods on the same node. Option E is not correct because a headless Service (clusterIP: None) deliberately has no virtual IP; it returns individual pod IPs via DNS records instead of a stable ClusterIP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ingress resources can be used for internal service discovery

    Why it's wrong here

    Ingress exposes HTTP and HTTPS routes from outside the cluster to internal Services; it is north-south traffic management, not service discovery. It is tempting because it references Services, but discovery is performed by Service objects and their DNS records.

  • ✗

    Service discovery is only available for pods on the same node

    Why it's wrong here

    Service discovery operates cluster-wide through kube-proxy and CoreDNS, so pods on any node can resolve and reach a Service. It is tempting if you picture node-local networking, but the mechanism is not scoped to a single node.

  • ✓

    Environment variables are injected into pods for each Service

    Why this is correct

    The kubelet injects environment variables for each active Service into newly created pods, exposing host and port values such as <SVCNAME>_SERVICE_HOST. This satisfies service discovery without DNS, though variables only reflect Services existing at pod creation time.

  • ✓

    Services are assigned a DNS name in the form <service>.<namespace>.svc.cluster.local

    Why this is correct

    CoreDNS resolves each Service to a cluster-scoped FQDN of the form <service>.<namespace>.svc.cluster.local, so pods reach backends by stable name rather than volatile pod IPs. This satisfies the service-discovery requirement by giving every Service a predictable, namespace-qualified DNS identity.

  • ✗

    Headless Services provide a stable virtual IP for service discovery

    Why it's wrong here

    A headless Service sets clusterIP to None, so it returns individual pod IPs via DNS rather than a stable virtual IP. It is tempting because it still provides discovery, but the virtual IP belongs to normal ClusterIP Services.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.