Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A developer wants to restrict network traffic so that only pods with label 'app: frontend' can communicate with pods labeled 'app: backend' on port 8080. Which Kubernetes resource should be used?

⚠ Common exam trap

Watch out — candidates often confuse NetworkPolicy with RBAC or security context controls, mistakenly thinking RoleBinding or PodSecurityPolicy can restrict network traffic, when in fact only NetworkPolicy (with a compatible CNI) provides pod-level network access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NetworkPolicy

A NetworkPolicy is the correct Kubernetes resource because it defines ingress and egress rules to control pod-to-pod communication based on labels, namespaces, and ports. By specifying a podSelector matching 'app: backend', an ingress rule allowing traffic from pods with label 'app: frontend' on port 8080, and a policyTypes field including 'Ingress', this resource enforces the desired restriction at the network layer using iptables or eBPF under the hood.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    NetworkPolicy

    Why this is correct

    NetworkPolicy is the correct Kubernetes resource for restricting network traffic to and from pods. It uses label selectors to match pods and defines ingress/egress rules in the spec, allowing you to control traffic at the IP/port level. For example, you can default-deny all ingress and then allow only from specific pod labels.

  • ✗

    ResourceQuota

    Why it's wrong here

    ResourceQuota does not manage network traffic at all; it constrains the total computed resources (CPU, memory) and the number of objects (services, PVCs) that can be created in a namespace. While it can indirectly affect workload scheduling, it cannot filter or block specific client-to-pod connections. Therefore it is wrong for this scenario.

  • ✗

    PodSecurityPolicy

    Why it's wrong here

    PodSecurityPolicy (PSP) enforces security constraints on pod specifications, such as allowed privilege escalation, host namespaces, and volume types. Although PSP was deprecated in Kubernetes 1.21 and replaced by Pod Security Admission, it never had any concept of network rules. Thus it cannot be used to restrict ingress/egress traffic.

  • ✗

    RoleBinding

    Why it's wrong here

    RoleBinding grants RBAC permissions to users, groups, or ServiceAccounts for Kubernetes API resources, like creating deployments or reading secrets. It operates on the control plane and has no effect on the pod data path or network packets. Selecting a RoleBinding would not change the traffic any pod can send or receive.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.