Networking & Service Discovery Flashcards
7 cards from real KCNA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Networking & Service Discovery flashcards as text
Which CNI plugin feature allows enforcement of NetworkPolicy objects?
Answer: Network policy enforcement by the CNI plugin
NetworkPolicy enforcement requires a CNI plugin that supports it (e.g., Calico, Cilium, Weave); the base CNI spec handles IP assignment and routing but not policy.
What is the default behavior for pod-to-pod communication when NO NetworkPolicy is applied?
Answer: All traffic is allowed between all pods
Without any NetworkPolicy, Kubernetes allows all pod-to-pod communication across the entire cluster by default.
Which Ingress feature allows routing different URL paths to different backend Services?
Answer: Path-based routing
Ingress path rules let you map HTTP paths like /api to one Service and /static to another Service within the same Ingress resource.
What is the role of CoreDNS in a Kubernetes cluster?
Answer: Provides DNS resolution for Service and pod names within the cluster
CoreDNS runs as a Deployment in the cluster and serves DNS queries, resolving Service names and pod hostnames to their respective IP addresses.
A Service of type ExternalName maps to what kind of resource?
Answer: A CNAME record pointing to an external DNS name
ExternalName Services create a DNS CNAME record that aliases the Service name to an external hostname, enabling cluster-internal resolution of external services.
Which field in a Service spec controls which port is exposed on the node when using NodePort type?
Answer: nodePort
The nodePort field (30000–32767 range) specifies which port on all cluster nodes is used to forward traffic to the Service.
What does the 'sessionAffinity: ClientIP' setting on a Service do?
Answer: Routes all requests from the same client IP to the same pod
ClientIP session affinity configures kube-proxy to forward all requests from a given client IP to the same backend pod for a configurable timeout period.