KCNA Kubernetes Fundamentals Practice Question
Which two of the following are valid ways to expose a set of Pods to external traffic?
⚠ Common exam trap
A common misconception is that an Ingress resource can function without an underlying Service, but Ingress only provides routing and must point to a Service to reach Pods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Service of type NodePort
Option A (Create a Service of type NodePort) is correct because a NodePort Service allocates a port on every node's IP (default range 30000-32767) and forwards external traffic to the selected Pods, making it a valid way to expose Pods externally. Option D (Create a Service of type LoadBalancer) is correct because it provisions an external load balancer (via the cloud provider) that routes traffic to the Service's endpoints, thereby exposing the Pods to external clients. Option B is incorrect because a ConfigMap stores configuration data, not network routing, and cannot expose Pods. Option C is incorrect because an Ingress resource requires a backing Service (typically ClusterIP) to route traffic to Pods; without a Service, it has no endpoints to forward to. Option E is incorrect because a ClusterIP Service only exposes Pods on an internal cluster IP, reachable only from within the cluster, not from external traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a Service of type NodePort
Why this is correct
NodePort opens a static port on every cluster node, forwarding external traffic to the matched Pods via kube-proxy. This satisfies the stem's requirement to expose Pods externally without a cloud load balancer, unlike ClusterIP, which remains reachable only inside the cluster.
- ✗
Use a ConfigMap to expose the Pods
Why it's wrong here
A ConfigMap stores configuration key-value data for consumption by Pods; it has no listener, virtual IP or routing rules, so it cannot receive or forward external traffic. It is tempting as a Kubernetes-native object, and it is correct for injecting configuration into Pods, not exposing them.
- ✗
Create an Ingress resource without a Service
Why it's wrong here
An Ingress routes HTTP traffic only to a Service, so without one it has no backend endpoints to forward to. It is tempting because Ingress is the standard external HTTP entry point, and it is correct when paired with a Service that selects the Pods.
- ✓
Create a Service of type LoadBalancer
Why this is correct
A LoadBalancer Service provisions an external load balancer through the cloud provider's controller, assigning a public IP that routes directly to the selected Pods. This satisfies the requirement to expose Pods to external traffic without manual ingress configuration, unlike ClusterIP, which remains cluster-internal only.
- ✗
Create a Service of type ClusterIP
Why it's wrong here
ClusterIP assigns a virtual IP reachable only from inside the cluster, so external clients cannot connect. It is tempting because it is the default Service type and does expose Pods, and it is correct for internal-only communication between workloads within the cluster.
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.