CKA Services and Networking Practice Question
A cluster administrator needs to allow pods labeled 'app=web' in namespace 'frontend' to receive TCP traffic on port 443 only from pods labeled 'app=proxy' in namespace 'backend'. The cluster uses the default CNI plugin that enforces NetworkPolicy. The administrator creates a NetworkPolicy in the 'frontend' namespace with podSelector matching 'app=web', policyTypes: ['Ingress'], and an ingress rule with from: [{namespaceSelector: {matchLabels: {name: 'backend'}}, podSelector: {matchLabels: {app: 'proxy'}}}], ports: [{protocol: 'TCP', port: 443}]. However, the namespace 'backend' is not labeled with 'name=backend'. What is the effect of this policy?
⚠ Common exam trap
The trap here is assuming that a namespaceSelector without a matching namespace label will allow all namespaces or be ignored, when in fact it results in no match and thus no allowed traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy allows traffic from pods with label 'app=proxy' in the 'backend' namespace only if the namespace is labeled 'name=backend'; otherwise, no traffic is allowed.
A NetworkPolicy ingress rule that combines namespaceSelector and podSelector in the same 'from' element requires both to match. The 'backend' namespace must have the label 'name=backend' for the rule to apply. Because it does not, the rule matches no sources, and the policy isolates the selected pods, denying all ingress traffic. Thus, no traffic is allowed until the namespace is labeled or the policy is adjusted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy allows traffic from any pod in the 'backend' namespace regardless of labels, because the podSelector is not required when namespaceSelector is present.
Why it's wrong here
The podSelector is required when specified; it is not ignored. The rule uses both namespaceSelector and podSelector in the same 'from' element, so both must match. Since the namespace lacks the label, the rule fails entirely. This option incorrectly suggests that the podSelector is optional, which would broaden access unintentionally.
- ✗
The policy allows traffic from pods with label 'app=proxy' in any namespace, because the namespaceSelector is ignored when the namespace lacks the label.
Why it's wrong here
The namespaceSelector is not ignored; it requires the namespace to have the specified label. If the 'backend' namespace lacks the label 'name=backend', the selector does not match, so traffic from pods in that namespace is not allowed. This option incorrectly assumes the namespaceSelector is bypassed when the label is absent, which would violate the intended isolation.
- ✓
The policy allows traffic from pods with label 'app=proxy' in the 'backend' namespace only if the namespace is labeled 'name=backend'; otherwise, no traffic is allowed.
Why this is correct
The ingress rule requires the source namespace to have the label 'name=backend' and the source pod to have the label 'app=proxy'. Because the 'backend' namespace is not labeled accordingly, the rule does not match any source, and since the policy selects 'app=web' pods and has an ingress policyType, it isolates them, denying all ingress traffic except what is explicitly allowed. Thus, no traffic is allowed.
- ✗
The policy allows traffic from pods with label 'app=proxy' in the 'backend' namespace, because the podSelector alone is sufficient to identify the source.
Why it's wrong here
In a NetworkPolicy ingress rule, when both namespaceSelector and podSelector are specified in the same 'from' element, they are combined with AND logic. Both the namespace must match the namespaceSelector and the pod must match the podSelector. Since the 'backend' namespace lacks the required label, the rule does not match, so this option is incorrect.
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.