CKA Services & Networking Practice Question
A Kubernetes cluster uses Calico as the CNI plugin. Two pods on different nodes cannot communicate, but pods on the same node can. Network policies are not enforced. What is the most likely cause?
⚠ Common exam trap
Watch out — candidates often assume Calico always uses an overlay (like Flannel) and pick Option A, missing the fact that Calico's default BGP mode is a direct routing approach that requires open ports, not an overlay.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The nodes' firewalls are blocking required ports for Calico (e.g., BGP port 179 or VXLAN port 4789).
Calico relies on specific ports for inter-node communication. When using BGP (default), port 179 must be open; when using VXLAN overlay, port 4789 is required. If node firewalls block these ports, Calico cannot establish routes or encapsulate traffic between nodes, causing cross-node pod communication to fail while same-node communication (which uses the local bridge) remains unaffected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Calico is not configured with an overlay network.
Why it's wrong here
Calico supports non-overlay networking (flat routed networks) using BGP to distribute routes directly to the physical network infrastructure. The absence of an overlay network (like VXLAN or IP-in-IP) is a valid architectural choice and does not inherently break pod-to-pod communication across nodes, provided the underlying network is routed correctly.
- ✗
A NetworkPolicy is blocking inter-node traffic.
Why it's wrong here
Since the scenario specifies that NetworkPolicies are not enforced or configured in this cluster, they cannot be the cause of the traffic disruption. Even if they were, NetworkPolicies typically regulate traffic at the pod selector level rather than targeting inter-node transport paths directly.
- ✗
The pods are using different Service types.
Why it's wrong here
Pod-to-pod communication in Kubernetes relies on direct IP routing provided by the CNI plugin, bypassing the Service layer entirely. The configuration or type of a Kubernetes Service (such as ClusterIP or NodePort) has no bearing on direct IP-based connectivity between individual pod endpoints.
- ✓
The nodes' firewalls are blocking required ports for Calico (e.g., BGP port 179 or VXLAN port 4789).
Why this is correct
Calico relies on specific control and data plane ports to establish inter-node connectivity, such as TCP port 179 for BGP routing or UDP port 4789 for VXLAN encapsulation. If host-level firewalls block these ports, nodes cannot exchange routing information or encapsulate cross-node pod traffic, breaking inter-node pod communication.
Go deeper
Related to this question
Learn chapter
Kubernetes Architecture Overview
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.