KCNA Kubernetes Fundamentals Practice Question
You want to expose a set of pods running a web application on port 80 internally within the cluster, with a stable IP address, so that other services can reach them. Which Kubernetes resource should you create?
⚠ Common exam trap
Watch out — candidates often confuse Ingress with internal service exposure, thinking it provides a stable internal IP, when in fact Ingress only handles external routing and requires a Service underneath.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Service (ClusterIP)
A Service of type ClusterIP provides a stable virtual IP address and DNS name that load-balances traffic to a set of pods. Since the requirement is internal cluster access with a stable IP, ClusterIP is the correct choice — it exposes the pods on a cluster-internal IP that other services can reach reliably, without needing external exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Service (ClusterIP)
Why this is correct
A ClusterIP Service allocates a stable virtual IP reachable only inside the cluster, exactly matching the internal exposure requirement. Its kube-proxy rules load-balance traffic across the selected pods on port 80, so other services get a consistent address despite pod restarts or rescheduling.
- ✗
Ingress
Why it's wrong here
Ingress routes external HTTP traffic to services and depends on an Ingress controller; it provides no stable internal cluster IP of its own. It is tempting because Ingress handles web traffic on port 80, but internal service-to-service reachability with a stable address requires a Service resource.
- ✗
Deployment
Why it's wrong here
A Deployment manages pod replicas and rolling updates but assigns no stable virtual IP; pod IPs change on recreation. It is tempting because Deployments run the web application, yet the requirement for a stable internal address on port 80 is satisfied by a Service, not the workload controller.
- ✗
Pod
Why it's wrong here
A Pod's IP is ephemeral and tied to that single replica, so it cannot provide a stable address or load-balance across the set. Pods are the workload unit a Service selects; a Service (ClusterIP) is what exposes them internally. Choosing Pod confuses the thing being exposed with the exposure mechanism itself.
Go deeper
Related to this question
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on KCNA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A team runs a stateless web application in Kubernetes. They have a Deployment named 'web-app' with 5 replicas. They want to ensure that a Service named 'web-svc' distributes traffic evenly to all healthy pods. Which type of Service should they use?
medium- ✓ A.ClusterIP
- B.Headless Service
- C.ExternalName Service
- D.NodePort
Why A: A ClusterIP Service is the correct choice because it provides a stable virtual IP address and round-robin load balancing across healthy pods in the Deployment. By default, kube-proxy uses iptables or IPVS rules to distribute traffic evenly to all ready pod endpoints, ensuring stateless web application requests are balanced without requiring external exposure.
Variation 2. A developer wants to expose a set of pods running a web application internally within the cluster using a stable IP address. Which Kubernetes resource should they create?
medium- A.Ingress
- B.ConfigMap
- C.Deployment
- ✓ D.Service
Why D: A Service of type ClusterIP provides a stable virtual IP address and DNS name that load-balances traffic to a set of pods, making it the correct resource for internal cluster exposure. Unlike other resources, a Service abstracts the pod IPs and ensures connectivity even if pods are rescheduled or scaled.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.