Courseiva
mediumMultiple Choice

CV0-004 Practice Question: Is deploying a containerized application using…

A cloud engineer is deploying a containerized application using Kubernetes. The application consists of a frontend, a backend API, and a database. The engineer needs to ensure that the backend API can be reached by the frontend but not from outside the cluster. Which Kubernetes resource should the engineer use to expose the backend API?

⚠ Common exam trap

Many candidates confuse Ingress as a method to expose services internally, but Ingress is specifically designed for external HTTP/HTTPS traffic and does not restrict access to cluster-internal communication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ClusterIP service

A ClusterIP service exposes the backend API on a cluster-internal IP address, making it reachable only from within the Kubernetes cluster. This meets the requirement that the frontend can communicate with the backend API, but external traffic is blocked. ClusterIP is the default service type and is ideal for internal service-to-service communication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    NodePort service

    Why it's wrong here

    A NodePort service opens the same static port on every cluster node's IP, publishing the backend API to anyone who can reach the node, which contradicts the requirement that it stay unreachable from outside. It is tempting because NodePort genuinely exposes a service without a cloud load balancer, but that exposure is precisely the wrong property here.

  • ✓

    ClusterIP service

    Why this is correct

    ClusterIP assigns a virtual IP reachable only inside the cluster network, so frontend pods can reach the backend API while external clients cannot. This satisfies the stem's requirement that the backend be unreachable from outside the cluster.

  • ✗

    Ingress resource

    Why it's wrong here

    An Ingress resource defines HTTP routing rules that terminate at an ingress controller exposed outside the cluster, so the backend API would become externally reachable, breaching the internal-only requirement. It is tempting because Ingress handles path-based routing between services, which suits exposing the frontend rather than isolating the backend.

  • ✗

    LoadBalancer service

    Why it's wrong here

    A LoadBalancer service provisions an external cloud load balancer with a public IP, routing traffic from outside the cluster to the backend API, directly violating the internal-only requirement. It is tempting because it is the standard way to publish a service externally, which is exactly what the frontend, not the backend, needs.

About these practice questions

Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.