Courseiva
Container Orchestration →hardMultiple Choice

KCNA Container Orchestration Practice Question

You have a microservices application with a frontend service that needs to communicate with a backend service running in a different namespace ('backend-ns'). The default namespace for the frontend is 'frontend-ns'. What DNS name should the frontend use to reach the backend service named 'backend-svc'?

⚠ Common exam trap

The trap here is that candidates often forget the 'svc' subdomain or mistakenly use the frontend's namespace instead of the backend's namespace, leading them to choose A or C, while D is a common shortcut that only works within the same namespace.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

backend-svc.backend-ns.svc.cluster.local

In Kubernetes, DNS names for services follow the pattern `<service>.<namespace>.svc.cluster.local`. Since the backend service 'backend-svc' is in the 'backend-ns' namespace, the correct DNS name is `backend-svc.backend-ns.svc.cluster.local`. This allows the frontend in 'frontend-ns' to resolve the backend service across namespaces.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    backend-svc.frontend-ns.svc.cluster.local

    Why it's wrong here

    This resolves backend-svc in frontend-ns, where no such service exists, so the lookup fails. The namespace segment must name the service's actual namespace, backend-ns. This form is correct only when caller and target share the same namespace.

  • ✓

    backend-svc.backend-ns.svc.cluster.local

    Why this is correct

    The fully qualified domain name resolves cross-namespace because Kubernetes DNS appends the namespace segment between service and svc. Since the frontend sits in frontend-ns while the backend runs in backend-ns, the short name backend-svc alone would fail; specifying backend-ns satisfies the cross-namespace constraint directly.

  • ✗

    backend-svc.backend-ns.cluster.local

    Why it's wrong here

    This fully qualified name resolves correctly from any namespace, so it is not the failure; the frontend could simply use 'backend-svc.backend-ns' since cluster.local is appended by default. The full FQDN is tempting for explicitness, and would be required when querying from outside the cluster or across clusters.

  • ✗

    backend-svc

    Why it's wrong here

    A bare service name resolves only within the same namespace via search domains; from frontend-ns it would look for backend-svc.frontend-ns.svc.cluster.local and fail. Short names suit same-namespace calls. Cross-namespace access needs the target namespace included in the DNS name.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.