CKAD Services and Networking Practice Question
A NetworkPolicy allows egress traffic to pods with label 'db: mysql' in the same namespace. Which egress rule is correct?
⚠ Common exam trap
It's easy for candidates to confuse the `from` field (used for ingress) with the `to` field (used for egress), or mistakenly use a `namespaceSelector` when a `podSelector` is required to target pods by label within the same namespace.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
egress: - to: - podSelector: matchLabels: db: mysql
A NetworkPolicy egress rule uses the `to` field to specify destination pods, and a `podSelector` within the same namespace selects pods with the label `db: mysql`. This allows outbound traffic from any pod in the namespace to pods matching that label, which directly satisfies the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
egress: - to: - podSelector: matchLabels: db: mysql
Why this is correct
This is correct because the egress rule uses the 'to' field, which is the required selector for defining destination traffic, and the podSelector with matchLabels 'db: mysql' limits allowed destinations only to pods carrying that label. The spec is otherwise valid because it requires no namespaceSelector, meaning it selects pods in the same namespace as the NetworkPolicy, which is the expected scope for this scenario. The policy permits egress only to those labeled pods while implicitly denying all other destinations.
- ✗
egress: - to: - namespaceSelector: matchLabels: db: mysql
Why it's wrong here
This rule is incorrect because namespaceSelector selects whole namespaces, not individual pods, so it would treat all pods in any namespace with label 'db: mysql' as allowed egress destinations. However, the requirement asks to allow traffic specifically to pods labeled 'db: mysql', not to every pod inside a namespace that happens to have that label. To match pods by their own label, the rule must use podSelector; namespaceSelector only filters based on namespace-level labels, which is a distinct and coarser-grained mechanism.
- ✗
egress: - from: - podSelector: matchLabels: db: mysql
Why it's wrong here
This rule is wrong because in egress rules, the peer selector must be under the 'to' field, not 'from'. The 'from' field is only valid in ingress rules, where it defines source pods, namespaces, or IP blocks; using it in egress is semantically invalid and will cause the API server to reject the policy. Even though the podSelector itself is correctly identifying pods with label 'db: mysql', placing it under 'from' inverts the direction and violates the NetworkPolicy schema.
- ✗
egress: - to: - ipBlock: cidr: 10.0.0.0/8
Why it's wrong here
This rule is invalid for the stated requirement because ipBlock matches by IP address ranges, not by pod labels, so it cannot specifically select pods carrying the label 'db: mysql'. A CIDR of 10.0.0.0/8 would allow egress to any pod in that large address range, potentially including unrelated pods, which is far broader than the intended label-based targeting. To honor the requirement, a podSelector must be used; ipBlock is only appropriate when you need to match based on IP addresses and not labels, which is not the case here.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.