KCNA Kubernetes Fundamentals Practice Question
Which TWO of the following are valid ways to expose a Deployment as a Service?
⚠ Common exam trap
Candidates often confuse 'kubectl run --expose' (which creates a Pod, not a Deployment) with exposing an existing Deployment, or incorrectly assume that a Deployment can contain a Service definition within its own YAML manifest.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run 'kubectl expose deployment my-deployment --port=80 --target-port=8080'
Option A is correct because 'kubectl expose deployment my-deployment --port=80 --target-port=8080' is the imperative command that creates a Service of type ClusterIP (by default) targeting the Deployment's pods, with the Service port 80 forwarding to container port 8080. Option E is correct because a Service is decoupled from the Deployment and selects its backing pods via 'spec.selector' matching the Deployment's pod template labels (e.g., app=my-deployment), so authoring a Service YAML with the correct selector is a valid declarative way to expose the Deployment. Option B is incorrect because 'spec.serviceName' is not a valid Deployment field; the closest concept, 'serviceName', belongs to StatefulSet's spec and is used for headless Service governance, not for exposing a Deployment. Option C is incorrect because 'kubectl run' creates a new Pod (or with newer versions a Pod), not a Deployment, and '--expose' would expose that newly created resource rather than an existing Deployment. Option D is incorrect because a Deployment's manifest has no 'service' section; Services are separate API objects (kind: Service) and cannot be embedded in a Deployment spec.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run 'kubectl expose deployment my-deployment --port=80 --target-port=8080'
Why this is correct
The imperative 'kubectl expose' command reads the Deployment's pod template, creates a Service with the matching label selector, and maps port 80 to container port 8080. It is a valid, supported way to expose a Deployment.
- ✗
Edit the Deployment and set 'spec.serviceName'
Why it's wrong here
There is no such field in a Deployment spec.
- ✗
Run 'kubectl run my-deployment --image=nginx --expose'
Why it's wrong here
This creates a pod and a Service, but does not use an existing Deployment.
- ✗
Add a 'service' section to the Deployment's YAML manifest
Why it's wrong here
Deployments do not have a service section; Services are separate resources.
- ✓
Create a Service YAML with a selector matching the Deployment's pod labels
Why this is correct
A Service routes traffic to pods via label selectors, so a YAML whose selector matches the Deployment's pod template labels creates an endpoint set for those pods. This satisfies the requirement to expose the Deployment without editing the workload itself.
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.