โ† All KCNA Flashcard Decks

Networking & Service Discovery Flashcards

7 cards from real KCNA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Networking & Service Discovery flashcards as text
  1. In a NetworkPolicy, what does an empty podSelector ({}) in the spec mean?

    Answer: All pods in the namespace are selected

    An empty podSelector matches all pods in the namespace where the NetworkPolicy is defined, applying the policy to every pod there.

  2. Which Kubernetes object defines layer 7 (HTTP/HTTPS) routing rules for external access to cluster services?

    Answer: Ingress

    Ingress resources define HTTP and HTTPS routing rules, host-based routing, and TLS termination for externally accessible services.

  3. What is an EndpointSlice in Kubernetes?

    Answer: A scalable group of network endpoints representing a subset of a Service's backends

    EndpointSlices replaced Endpoints for scalability, grouping backend pod IPs and ports into slices of up to 100 entries per slice.

  4. Which kube-proxy mode uses Linux kernel's IPVS (IP Virtual Server) for load balancing?

    Answer: ipvs mode

    IPVS mode in kube-proxy uses the kernel's IPVS framework, which offers better performance and more load balancing algorithms than iptables for large clusters.

  5. What does the 'externalTrafficPolicy: Local' setting on a NodePort or LoadBalancer Service do?

    Answer: Preserves the client's source IP and only routes to pods on the receiving node

    With Local policy, kube-proxy only forwards to pods on the same node that received the traffic, preserving the original client IP but potentially causing uneven load distribution.

  6. Which DNS record type does Kubernetes use for headless Service pods with a stable hostname (StatefulSet)?

    Answer: A record per pod hostname

    For headless Services backed by StatefulSets, each pod gets an A record of the form ...svc.cluster.local.

  7. What is the cluster CIDR used for in Kubernetes networking?

    Answer: Assigning IP addresses to pods across the cluster

    The cluster CIDR (e.g., 10.244.0.0/16) is the IP address range from which pod IPs are allocated across all nodes.