Courseiva
Services and Networking →hardMultiple Choice

CKA Services and Networking Practice Question

You apply the following NetworkPolicy: ```yaml apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: deny-all spec: podSelector: {} policyTypes: - Ingress - Egress ``` What is the result?

⚠ Common exam trap

A common mix-up: candidates assume an empty `podSelector` or missing rules means 'allow all', but Kubernetes NetworkPolicy defaults to deny when a policy selects a pod and no matching rule is present.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

All ingress and egress traffic to/from all pods in the namespace is denied

This NetworkPolicy uses an empty `podSelector: {}` which selects all pods in the namespace. By specifying both `Ingress` and `Egress` in `policyTypes` without any rules, the policy defaults to denying all ingress and egress traffic for those pods. This is the standard Kubernetes behavior: a NetworkPolicy with no rules under a given `policyTypes` entry acts as a deny-all for that direction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    All traffic is allowed because no ingress/egress rules are specified

    Why it's wrong here

    In Kubernetes NetworkPolicies, specifying `policyTypes` containing both `Ingress` and `Egress` without defining any corresponding `ingress` or `egress` rule blocks creates an isolation boundary. This configuration acts as an explicit "default deny" mechanism rather than a "default allow". Consequently, all incoming and outgoing network connections are blocked for the selected pods, rather than permitted.

  • ✗

    Only ingress traffic is denied; egress traffic is allowed

    Why it's wrong here

    Because the `policyTypes` list explicitly includes both `Ingress` and `Egress`, the policy enforces isolation on both traffic directions simultaneously. If only `Ingress` were listed, egress traffic would indeed remain unaffected and allowed. However, since `Egress` is declared without any matching whitelist rules, all outbound traffic from the selected pods is blocked.

  • ✓

    All ingress and egress traffic to/from all pods in the namespace is denied

    Why this is correct

    This YAML defines a classic "default-deny-all" policy for the namespace. By using an empty `podSelector: {}`, the policy targets every pod in the namespace. Since both `Ingress` and `Egress` are specified in `policyTypes` but no actual allow rules are defined in the body, all incoming and outgoing network traffic is completely blocked for these pods.

  • ✗

    The policy is invalid because podSelector is empty

    Why it's wrong here

    In Kubernetes API design, an empty `podSelector: {}` is syntactically valid and has a specific semantic meaning: it selects all pods within the namespace where the NetworkPolicy is applied. This is a standard pattern used by administrators to establish a baseline security posture. It should not be confused with omitting the `podSelector` field entirely, which can lead to different default behaviors depending on the schema version.

About these practice questions

This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.