Networking & Service Discovery Flashcards
7 cards from real KCNA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Networking & Service Discovery flashcards as text
In a NetworkPolicy, what does an empty podSelector ({}) in the spec mean?
Answer: All pods in the namespace are selected
An empty podSelector matches all pods in the namespace where the NetworkPolicy is defined, applying the policy to every pod there.
Which Kubernetes object defines layer 7 (HTTP/HTTPS) routing rules for external access to cluster services?
Answer: Ingress
Ingress resources define HTTP and HTTPS routing rules, host-based routing, and TLS termination for externally accessible services.
What is an EndpointSlice in Kubernetes?
Answer: A scalable group of network endpoints representing a subset of a Service's backends
EndpointSlices replaced Endpoints for scalability, grouping backend pod IPs and ports into slices of up to 100 entries per slice.
Which kube-proxy mode uses Linux kernel's IPVS (IP Virtual Server) for load balancing?
Answer: ipvs mode
IPVS mode in kube-proxy uses the kernel's IPVS framework, which offers better performance and more load balancing algorithms than iptables for large clusters.
What does the 'externalTrafficPolicy: Local' setting on a NodePort or LoadBalancer Service do?
Answer: Preserves the client's source IP and only routes to pods on the receiving node
With Local policy, kube-proxy only forwards to pods on the same node that received the traffic, preserving the original client IP but potentially causing uneven load distribution.
Which DNS record type does Kubernetes use for headless Service pods with a stable hostname (StatefulSet)?
Answer: A record per pod hostname
For headless Services backed by StatefulSets, each pod gets an A record of the form ...svc.cluster.local.
What is the cluster CIDR used for in Kubernetes networking?
Answer: Assigning IP addresses to pods across the cluster
The cluster CIDR (e.g., 10.244.0.0/16) is the IP address range from which pod IPs are allocated across all nodes.