CKA Services and Networking Practice Question
You apply the following NetworkPolicy: ```yaml apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: deny-all spec: podSelector: {} policyTypes: - Ingress - Egress ``` What is the result?
⚠ Common exam trap
A common mix-up: candidates assume an empty `podSelector` or missing rules means 'allow all', but Kubernetes NetworkPolicy defaults to deny when a policy selects a pod and no matching rule is present.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
All ingress and egress traffic to/from all pods in the namespace is denied
This NetworkPolicy uses an empty `podSelector: {}` which selects all pods in the namespace. By specifying both `Ingress` and `Egress` in `policyTypes` without any rules, the policy defaults to denying all ingress and egress traffic for those pods. This is the standard Kubernetes behavior: a NetworkPolicy with no rules under a given `policyTypes` entry acts as a deny-all for that direction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All traffic is allowed because no ingress/egress rules are specified
Why it's wrong here
In Kubernetes NetworkPolicies, specifying `policyTypes` containing both `Ingress` and `Egress` without defining any corresponding `ingress` or `egress` rule blocks creates an isolation boundary. This configuration acts as an explicit "default deny" mechanism rather than a "default allow". Consequently, all incoming and outgoing network connections are blocked for the selected pods, rather than permitted.
- ✗
Only ingress traffic is denied; egress traffic is allowed
Why it's wrong here
Because the `policyTypes` list explicitly includes both `Ingress` and `Egress`, the policy enforces isolation on both traffic directions simultaneously. If only `Ingress` were listed, egress traffic would indeed remain unaffected and allowed. However, since `Egress` is declared without any matching whitelist rules, all outbound traffic from the selected pods is blocked.
- ✓
All ingress and egress traffic to/from all pods in the namespace is denied
Why this is correct
This YAML defines a classic "default-deny-all" policy for the namespace. By using an empty `podSelector: {}`, the policy targets every pod in the namespace. Since both `Ingress` and `Egress` are specified in `policyTypes` but no actual allow rules are defined in the body, all incoming and outgoing network traffic is completely blocked for these pods.
- ✗
The policy is invalid because podSelector is empty
Why it's wrong here
In Kubernetes API design, an empty `podSelector: {}` is syntactically valid and has a specific semantic meaning: it selects all pods within the namespace where the NetworkPolicy is applied. This is a standard pattern used by administrators to establish a baseline security posture. It should not be confused with omitting the `podSelector` field entirely, which can lead to different default behaviors depending on the schema version.
Go deeper
Related to this question
Learn chapter
Services and Networking Fundamentals
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.