CKA Services and Networking Practice Question
Which NetworkPolicy rule will allow ingress traffic from pods with label 'role: frontend' in the same namespace?
⚠ Common exam trap
Test-takers frequently confuse `podSelector` (which selects pods in the same namespace) with `namespaceSelector` (which selects namespaces), or they mistakenly choose an egress rule when the question explicitly asks for ingress traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ingress: - from: - podSelector: matchLabels: role: frontend
A NetworkPolicy ingress rule with a `podSelector` matches pods in the same namespace as the policy. By specifying `matchLabels: role: frontend`, it allows inbound traffic from any pod in the same namespace that has that label, which is exactly what the question requires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ingress: - from: - podSelector: matchLabels: role: frontend
Why this is correct
The `from` section with a `podSelector` selects source pods by their labels, and because the selector is placed directly under `ingress`, it governs inbound traffic. This rule allows traffic only from pods in the same namespace that carry the label `role: frontend`, which is exactly the intended behavior. It correctly targets pod identity rather than IP ranges or namespace identity, making it the right choice.
- ✗
ingress: - from: - ipBlock: cidr: 0.0.0.0/0
Why it's wrong here
An `ipBlock` with `cidr: 0.0.0.0/0` matches every IPv4 address, from external clients to cluster nodes, but it cannot evaluate pod labels. The requirement is to allow ingress from pods with a specific label, whereas an IP-based rule ignores labels and would permit far broader sources. Overly permissive network policies like this increase the attack surface and do not fulfill the label-based constraint.
- ✗
egress: - to: - podSelector: matchLabels: role: frontend
Why it's wrong here
This rule is an `egress` rule, which controls outbound connections originating from the selected pods, not inbound connections arriving at a pod. Even if the `podSelector` correctly identifies the desired peers, placing it under `egress` means it would allow those pods to send traffic out, not receive traffic in. The question is about ingress, so the direction is wrong regardless of the selector.
- ✗
ingress: - from: - namespaceSelector: matchLabels: role: frontend
Why it's wrong here
A `namespaceSelector` matches namespaces based on their labels, and this rule would allow traffic from any pod that resides in a namespace labeled `role: frontend`. It does not filter by the labels of the individual source pods, so it could include pods with other roles within that namespace. Since the requirement is to allow traffic specifically from pods carrying `role: frontend`, this selector is too broad and misdirected.
About these practice questions
Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.