CKA Services and Networking Practice Question
You have a NetworkPolicy that denies all ingress traffic by default, and you want to allow traffic only from pods with label 'app: monitoring' in the same namespace. What should the policy spec look like?
⚠ Common exam trap
The trap here is that candidates often add a namespaceSelector unnecessarily, thinking it is required to restrict to the same namespace, when in fact omitting the namespaceSelector automatically limits the rule to the policy's namespace.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ingress: - from: - podSelector: matchLabels: app: monitoring
A NetworkPolicy with an ingress rule using only a podSelector allows traffic from pods matching the specified labels within the same namespace. Since the default policy denies all ingress traffic, this rule explicitly permits traffic from pods labeled 'app: monitoring' in the same namespace, which satisfies the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ingress: - from: - ipBlock: cidr: 0.0.0.0/0
Why it's wrong here
Specifying an ipBlock with the CIDR 0.0.0.0/0 opens up ingress traffic to all external and internal IP addresses, completely bypassing the default-deny behavior. This is highly insecure and overly permissive, failing to restrict traffic specifically to the designated monitoring pods. Additionally, ipBlock is typically used for traffic originating outside the cluster rather than pod-to-pod communication.
- ✗
ingress: - from: - podSelector: matchLabels: app: monitoring - namespaceSelector: matchLabels: name: my-namespace
Why it's wrong here
This configuration uses a single array item containing both podSelector and namespaceSelector, which acts as an AND condition. It restricts traffic to pods labeled app: monitoring that also reside in namespaces labeled name: my-namespace. This is overly restrictive because it requires the target namespace to have a specific label, and it fails if the current namespace does not match that label.
- ✓
ingress: - from: - podSelector: matchLabels: app: monitoring
Why this is correct
This is the correct configuration because omitting the namespaceSelector entirely defaults the scope of the podSelector to the same namespace where the NetworkPolicy is applied. It successfully permits ingress traffic exclusively from pods labeled app: monitoring within the local namespace. This precisely satisfies the requirement of isolating traffic to specific local pods while maintaining the default-deny rule for everything else.
- ✗
ingress: - from: - namespaceSelector: matchLabels: app: monitoring
Why it's wrong here
Using namespaceSelector on its own selects entire namespaces rather than individual pods. This configuration would allow ingress traffic from any pod residing inside any namespace labeled app: monitoring. This is a significant security risk as it does not restrict traffic to the specific monitoring pods, violating the principle of least privilege.
About these practice questions
Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.