Courseiva
Container Orchestration →mediumMultiple Choice

KCNA Container Orchestration Practice Question

You need to ensure that a set of pods in a Deployment can be reached by other pods using a stable IP address and DNS name. Which Kubernetes object should you use?

⚠ Common exam trap

It's easy for candidates to confuse Ingress (external HTTP routing) with internal service discovery, or think NetworkPolicy provides addressing, when only a Service offers a stable virtual IP and DNS name for pod-to-pod communication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Service

A Service provides a stable IP address and DNS name for a set of pods, abstracting the underlying pod IPs that can change due to scaling or failures. By default, a Service uses a cluster-internal virtual IP and DNS record (e.g., <service-name>.<namespace>.svc.cluster.local) that other pods can resolve, ensuring reliable connectivity without needing to track individual pod IPs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Service

    Why this is correct

    A Service provides a stable virtual IP address and DNS name that load-balances traffic across the Deployment's pods, satisfying the reachability requirement. Pod IPs are ephemeral, so clients must target the Service rather than individual pod addresses.

  • ✗

    NetworkPolicy

    Why it's wrong here

    NetworkPolicy controls ingress and egress traffic between pods, not service discovery or address stability, so it cannot supply a stable IP or DNS name. It is tempting because it governs pod connectivity, and it would be the right choice when restricting which pods may communicate with a workload.

  • ✗

    Ingress

    Why it's wrong here

    Ingress routes external HTTP/HTTPS traffic into the cluster via host- or path-based rules, so it cannot supply a stable internal IP and DNS name for pod-to-pod traffic. It is tempting because it does provide a stable DNS name, but only for inbound clients; a Service is the object that gives pods a stable virtual IP and cluster DNS entry.

  • ✗

    ConfigMap

    Why it's wrong here

    A ConfigMap stores non-confidential configuration as key–value pairs consumed by pods via environment variables or mounted files; it provides no virtual IP, no kube-proxy load-balancing rule and no cluster DNS record, so it cannot expose pods. It is tempting because it also decouples configuration from pod specs, and would be correct for injecting application settings or config files.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.