CKAD Services and Networking Practice Question
A NetworkPolicy denies all ingress traffic to a namespace. Which rule would allow traffic only from pods in the same namespace?
⚠ Common exam trap
Many candidates confuse the empty `podSelector: {}` (which matches all pods in the local namespace) with a `namespaceSelector: {}` (which matches all namespaces), leading them to choose Option A, which inadvertently allows traffic from all namespaces instead of only the same namespace.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
from: - podSelector: {}
A `podSelector: {}` in a NetworkPolicy ingress rule selects all pods in the same namespace as the policy, effectively allowing traffic only from pods within that namespace. This works because the empty podSelector matches all pods in the namespace where the NetworkPolicy is applied, and no namespaceSelector is specified, so the rule is scoped to the local namespace only.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
from: - namespaceSelector: {} podSelector: {}
Why it's wrong here
Using an empty namespaceSelector alongside an empty podSelector expands the scope to every pod in every namespace across the cluster. Because namespaceSelector: {} matches all namespaces, and podSelector: {} matches all pods within those namespaces, this rule permits ingress from any pod in any namespace, violating the intended restriction to only the policy's own namespace. This is a common mistake when trying to select 'all pods' without realizing the namespaceSelector broadens the selection globally.
- ✗
from: - ipBlock: cidr: 0.0.0.0/0
Why it's wrong here
An ipBlock rule with cidr 0.0.0.0/0 allows ingress from every IPv4 address, including sources outside the cluster entirely. This bypasses the pod-based identity model of NetworkPolicies, as it filters on raw IP addresses rather than Kubernetes labels or namespaces. Since the goal is to permit only traffic from pods in the same namespace, this rule is far too permissive and also fails to enforce any namespace or pod association.
- ✓
from: - podSelector: {}
Why this is correct
An empty podSelector with no namespaceSelector correctly limits the source to pods in the same namespace as the NetworkPolicy. In Kubernetes NetworkPolicy semantics, when only podSelector is specified, it implicitly selects pods within the policy's own namespace and does not affect other namespaces. Therefore, this rule allows ingress from all pods in that namespace while blocking traffic from other namespaces and external sources, matching the requirement precisely.
- ✗
from: - namespaceSelector: matchLabels: name: mynamespace
Why it's wrong here
This namespaceSelector targets a namespace labeled 'name: mynamespace', but it does not guarantee that the selected namespace is the same as the one where the policy is applied. If the policy's namespace lacks that label, or if another namespace carries the same label, traffic from that other namespace will be allowed, which may violate the intended same-namespace-only rule. Additionally, this rule selects all pods in the labeled namespace, not just the policy's own namespace, making it both namespace-external and overly broad.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.