Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A developer wants to restrict a Pod's resource usage. Which two API resources can be used to enforce limits at the namespace level? (Choose two.)

⚠ Common exam trap

CNCF often tests the distinction between namespace-level resource enforcement (LimitRange and ResourceQuota) and cluster-level or scaling mechanisms, leading candidates to confuse HorizontalPodAutoscaler (which scales Pods) with resource limits.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

LimitRange

LimitRange (C) is correct because it allows administrators to set default resource requests and limits, as well as minimum and maximum constraints, for Pods and containers within a namespace. This enforces resource boundaries at the namespace level, ensuring that individual Pods cannot exceed defined limits.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PodSecurityPolicy

    Why it's wrong here

    PodSecurityPolicy is a cluster-level admission controller that historically enforced security-related constraints, such as privileged mode, host namespaces, and volume types, but it never governed CPU or memory consumption. It was deprecated in Kubernetes v1.21 and removed entirely in v1.25 in favor of Pod Security Admission, so it is both obsolete and incapable of restricting a pod's resource usage.

  • ✗

    HorizontalPodAutoscaler

    Why it's wrong here

    HorizontalPodAutoscaler (HPA) dynamically adjusts the number of pod replicas in a workload based on observed CPU or memory utilization, aiming to match current demand. It only changes the replica count; it does not define or enforce any per-pod resource ceiling. Without a LimitRange or ResourceQuota, an HPA can actually scale up to many pods that each consume unbounded resources, worsening resource overuse rather than restricting it.

  • ✓

    LimitRange

    Why this is correct

    A LimitRange is a namespaced Kubernetes object that sets minimum, maximum, and default values for CPU and memory requests and limits for individual containers or pods. When a container is created without explicit resources, the LimitRange admission plugin automatically injects defaults, and if the container's declared limits fall outside the configured range, the pod is rejected. This gives operators precise, per-pod control over how many resources each workload can consume.

  • ✓

    ResourceQuota

    Why this is correct

    A ResourceQuota enforces an aggregate budget on the total CPU request, memory request, CPU limit, memory limit, and other object counts within a namespace. Each pod creation is validated against the remaining quota: if the pod's resource requests or limits would push the namespace totals above the hard limits, the API server denies the operation. This prevents a single developer from exhausting the entire cluster's resources, regardless of how many pods are created.

  • ✗

    NetworkPolicy

    Why it's wrong here

    NetworkPolicy is a namespaced resource used to secure traffic at the network layer by defining ingress and egress rules based on pod labels, namespace selectors, and IP CIDR blocks. It only affects connectivity and data flow; it has zero impact on scheduling, container runtime limits, or the kubelet's enforcement of resource constraints. CPU and memory caps must be set via the pod spec directly, LimitRange, or ResourceQuota, so NetworkPolicy cannot solve the problem at hand.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.