KCNA Container Orchestration Practice Question
You are asked to deploy a Kubernetes service that exposes a set of pods internally within the cluster only. The service should not be accessible from outside the cluster. Which Service type should you choose?
⚠ Common exam trap
CNCF often tests the misconception that ClusterIP is only for inter-pod communication within the same namespace, but it actually works across all namespaces within the cluster, and the trap is that candidates confuse it with NodePort when they think 'internal only' means 'no external access' but forget that NodePort inherently opens external access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ClusterIP
ClusterIP is the default Kubernetes Service type that exposes the service on a cluster-internal IP address. This makes the service reachable only from within the cluster, which is exactly what is required for internal-only communication between pods. No external traffic can reach a ClusterIP service unless an ingress controller or proxy is explicitly configured.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ClusterIP
Why this is correct
ClusterIP assigns a virtual IP reachable only from within the cluster, satisfying the internal-only constraint. Unlike NodePort or LoadBalancer, it provisions no external listener or cloud load balancer, so pods remain unexposed outside the cluster network.
- ✗
NodePort
Why it's wrong here
NodePort opens a static port on every node's IP, making the Service reachable from outside the cluster, which directly violates the internal-only requirement. ClusterIP restricts access to within the cluster. Tempting for quick external access during testing, but that is exactly what the scenario forbids.
- ✗
ExternalName
Why it's wrong here
ExternalName maps a Service to a DNS CNAME record, providing no cluster-internal virtual IP or pod selection at all. ClusterIP is the type that exposes pods internally only. Tempting when referencing external databases by DNS name, but it cannot front a set of pods or satisfy internal-only exposure.
- ✗
LoadBalancer
Why it's wrong here
LoadBalancer provisions an external cloud load balancer with a public IP, exposing the Service outside the cluster and contradicting the internal-only requirement. ClusterIP keeps traffic cluster-internal. Tempting when internet-facing ingress is needed, but the stem explicitly rules out external accessibility.
Go deeper
Related to this question
Learn chapter
Pods and Workload Management
Key term
Kubernetes API Primitives
Kubernetes API Primitives are the basic building blocks that the Kubernetes API uses to represent and manage the state of a cluster, such as Pods, Services, Deployments, and Namespaces.
Key term
ReplicaSet and Replication
A ReplicaSet ensures a specified number of identical pod instances are running at all times in Kubernetes, using replication to maintain availability and stability.
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.