โ† All KCNA Flashcard Decks

Networking & Service Discovery Flashcards

7 cards from real KCNA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Networking & Service Discovery flashcards as text
  1. Which component is responsible for watching Service and Endpoints changes and updating node-level routing rules?

    Answer: kube-proxy

    kube-proxy runs on every node, watches the API server for Service and Endpoint changes, and updates iptables or IPVS rules accordingly.

  2. In Kubernetes, what is a 'Service Topology' feature used for?

    Answer: Routing Service traffic preferentially to endpoints in the same zone or node

    Service Topology allows traffic to be routed preferentially to endpoints topologically close to the client, such as same-node or same-zone, reducing latency and cross-zone costs.

  3. What is the purpose of a NetworkPolicy's 'namespaceSelector'?

    Answer: To allow or deny traffic from pods in specific namespaces

    namespaceSelector in NetworkPolicy ingress/egress rules matches namespaces by label, controlling which namespaces' pods can communicate with the selected pods.

  4. Which Service discovery mechanism do pods use by default when environment variable injection is enabled?

    Answer: Environment variables injected at pod start for each active Service

    Kubernetes injects environment variables like _SERVICE_HOST and _SERVICE_PORT into each pod at startup for all Services that existed before the pod.

  5. What is the function of the 'targetPort' field in a Service spec?

    Answer: The port on the pod/container that the Service forwards traffic to

    targetPort specifies the actual port on the pod container to which the Service forwards incoming traffic, and can be a number or a named port.

  6. Which Cilium feature goes beyond standard NetworkPolicy to provide identity-based security at L3/L4/L7?

    Answer: CiliumNetworkPolicy

    CiliumNetworkPolicy is a CRD that extends standard NetworkPolicy with L7 rules (e.g., HTTP methods, paths) and identity-based enforcement using eBPF.

  7. In the context of service meshes, what is 'mTLS' used for between services?

    Answer: Mutual TLS for encrypted and mutually authenticated pod-to-pod communication

    Mutual TLS (mTLS) ensures both the client and server authenticate each other with certificates, encrypting service-to-service traffic in a service mesh like Istio or Linkerd.