XK0-006 Automation, Orchestration, and Scripting Practice Question
A Kubernetes administrator needs to expose a deployment named 'web-app' running on port 80 internally within the cluster. Which kubectl command creates a service of type ClusterIP that maps port 80 to the target port 8080 on the pods?
⚠ Common exam trap
XK0-006 often tests the difference between exposing a deployment vs. a pod, and between ClusterIP/NodePort/LoadBalancer service types — candidates pick 'create service nodeport' or expose a pod, missing that the default type is ClusterIP and that deployments should be exposed for scalability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl expose deployment web-app --port=80 --target-port=8080
The command 'kubectl expose deployment web-app --port=80 --target-port=8080' creates a Service of type ClusterIP (the default) that exposes the deployment 'web-app'. The --port flag sets the Service port to 80, and --target-port sets the container port to 8080, correctly mapping Service port 80 to pod port 8080.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl create service nodeport web-app --tcp=80:8080
Why it's wrong here
NodePort allocates a port on every node and exposes the service externally, whereas the requirement is internal cluster-only access. It is tempting because the port mapping syntax is identical and it still creates a working service, and NodePort would be correct when external clients must reach the deployment without an ingress controller or load balancer.
- ✓
kubectl expose deployment web-app --port=80 --target-port=8080
Why this is correct
`kubectl expose deployment web-app --port=80 --target-port=8080` generates a ClusterIP service, the default type, satisfying the internal-only requirement. The `--port` flag sets the service port to 80, while `--target-port=8080` directs traffic to the container's listening port, correctly mapping the mismatch between service and pod ports.
- ✗
kubectl expose pod web-app --port=80 --target-port=8080
Why it's wrong here
Exposing a pod directly with `kubectl expose pod` creates a service that routes traffic to that single pod, not to the `web-app` deployment’s replica set. The stem requires exposing a *deployment*, which manages multiple pods and provides load balancing and self-healing; the correct command targets the deployment resource (`kubectl expose deployment web-app ...`). This option is tempting because `kubectl expose pod` works correctly when the goal is to expose a standalone pod that is not managed by a higher-level controller, such as during debugging or testing a single instance.
- ✗
kubectl create service clusterip web-app --tcp=80:8080
Why it's wrong here
The syntax is incorrect; --tcp expects a different format.
Go deeper
Related to this question
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.