CKA Services and Networking Practice Question
Which THREE statements about NetworkPolicy are correct?
⚠ Common exam trap
A common misconception is that NetworkPolicy defaults to deny-all when no policy exists, but the actual default is allow-all; the trap is that candidates confuse the 'default deny' behavior that occurs once a policy selects a pod (if no rule allows traffic) with the cluster-wide default.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To allow traffic from a specific namespace, you can use a namespaceSelector in the ingress rule.
Option A is correct because an ingress rule's 'from' clause can include a namespaceSelector that matches namespaces by their labels, thereby permitting traffic originating from pods in those namespaces. Option C is correct because an empty podSelector (podSelector: {}) matches every pod in the NetworkPolicy's own namespace, effectively applying the policy to all pods there. Option D is correct because podSelector uses a LabelSelector whose matchLabels field selects pods by exact key/value label pairs. Option B is wrong because the absence of any NetworkPolicy means all ingress and egress traffic is allowed by default; traffic is only denied once a policy selects the pod. Option E is wrong because NetworkPolicy is a namespaced resource, not cluster-scoped, and only affects pods within its own namespace.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
To allow traffic from a specific namespace, you can use a namespaceSelector in the ingress rule.
Why this is correct
A namespaceSelector matches pods by their namespace's labels, so an ingress rule containing it permits traffic originating from pods in the selected namespace. This satisfies the stem's requirement for allowing traffic from a specific namespace.
- ✗
If no NetworkPolicy exists, all traffic is denied by default.
Why it's wrong here
Kubernetes applies an implicit allow-all when no NetworkPolicy selects a pod; isolation begins only once a policy exists. It is tempting because default-deny is a common hardening posture, but that requires an explicit deny-all policy, not the absence of one.
- ✓
A NetworkPolicy with podSelector: {} selects all pods in the namespace.
Why this is correct
An empty podSelector matches every pod within the policy's own namespace, satisfying the requirement to select all pods there. NetworkPolicies are namespace-scoped, so this selector does not reach pods in other namespaces. Combined with an empty ingress or egress rule, it denies all traffic to or from those selected pods.
- ✓
The field 'podSelector.matchLabels' is used to select pods based on labels.
Why this is correct
NetworkPolicy selects the pods it applies to through the podSelector field, whose matchLabels map matches pods by their labels. This label-based selection is the mechanism that scopes the policy to specific workloads within the namespace.
- ✗
NetworkPolicy is a cluster-scoped resource.
Why it's wrong here
NetworkPolicy is namespaced, not cluster-scoped, so it cannot be created at cluster level or selected across namespaces. It is tempting because ClusterRole, PersistentVolume and StorageClass are genuinely cluster-scoped, and a cluster-scoped policy would be the right choice for enforcing rules across every namespace at once.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.