CKA Services and Networking Practice Question
Which FOUR are correct ways to configure a default deny all ingress traffic NetworkPolicy? (Choose 4)
⚠ Common exam trap
The exam often tests the subtle difference between `from: []` (empty array, denies all) and `from: [{}]` (empty object, allows all), as well as the fact that a NetworkPolicy with no rules at all (only podSelector) still enforces a default deny, which candidates may mistakenly think requires an explicit empty ingress list.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A NetworkPolicy with podSelector: {} and an ingress rule with from: []
Option C is correct because `podSelector: {}` selects all pods in the namespace and `ingress: []` defines an empty ingress rule set, which denies all ingress traffic to those pods. Option D is correct because a NetworkPolicy with `podSelector: {}` and no rules at all (only metadata and spec) has no ingress rules, so it isolates all selected pods and denies all ingress by default. Option E is correct because omitting the `ingress` field entirely is equivalent to having an empty ingress rule set, which denies all ingress traffic to the selected pods. Option A is also correct: an ingress rule with `from: []` contains an empty list of sources, which matches no sources and therefore allows no ingress traffic; the presence of the rule does not permit traffic because no source matches. Option B is incorrect because `from: [{}]` contains an empty object, which matches all sources and therefore allows all ingress traffic, the opposite of deny all.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A NetworkPolicy with podSelector: {} and an ingress rule with from: []
Why this is correct
An empty from list does not match any sources, but the rule itself is an ingress rule; however, it still results in no allowed traffic, but it's not a default deny pattern (it's an allow rule that allows nothing). The classic default deny has no ingress rules.
- ✗
A NetworkPolicy with podSelector: {} and an ingress rule with from: [{}]
Why it's wrong here
Specifying an empty object within the from block of an ingress rule acts as a wildcard that matches all namespaces and all pods. Instead of denying traffic, this configuration explicitly allows all incoming traffic from any source inside or outside the cluster, completely defeating the purpose of a default-deny policy.
- ✓
A NetworkPolicy with podSelector: {} and ingress: []
Why this is correct
Defining ingress as an empty list explicitly sets the list of allowed ingress rules to empty, meaning no incoming traffic matches any allow criteria. Because the policy targets all pods in the namespace via an empty podSelector and lists Ingress in its policyTypes, this empty list successfully isolates the namespace by denying all inbound connections.
- ✓
A NetworkPolicy with podSelector: {} and no rules at all (only metadata and spec)
Why this is correct
When a NetworkPolicy defines Ingress in its policyTypes but completely omits the ingress key from its specification, Kubernetes defaults to allowing no ingress traffic. Since the podSelector is empty, it selects all pods in the namespace, and the absence of any ingress rules ensures that all incoming traffic to these pods is blocked.
- ✓
A NetworkPolicy with podSelector: {} and no ingress rules
Why this is correct
Selecting all pods in a namespace using an empty podSelector while declaring Ingress under policyTypes without defining any actual ingress rules triggers the default-deny behavior. Because NetworkPolicies act as an additive whitelist, the lack of any explicit allow rules means that all incoming traffic to the targeted pods is rejected by default.
Visual reference
About these practice questions
Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.