Courseiva
Services and Networking →mediumMultiple Choice

CKAD Services and Networking Practice Question

A NetworkPolicy denies all ingress traffic to a namespace. Which rule would allow traffic only from pods in the same namespace?

⚠ Common exam trap

Many candidates confuse the empty `podSelector: {}` (which matches all pods in the local namespace) with a `namespaceSelector: {}` (which matches all namespaces), leading them to choose Option A, which inadvertently allows traffic from all namespaces instead of only the same namespace.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

from: - podSelector: {}

A `podSelector: {}` in a NetworkPolicy ingress rule selects all pods in the same namespace as the policy, effectively allowing traffic only from pods within that namespace. This works because the empty podSelector matches all pods in the namespace where the NetworkPolicy is applied, and no namespaceSelector is specified, so the rule is scoped to the local namespace only.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    from: - namespaceSelector: {} podSelector: {}

    Why it's wrong here

    Using an empty namespaceSelector alongside an empty podSelector expands the scope to every pod in every namespace across the cluster. Because namespaceSelector: {} matches all namespaces, and podSelector: {} matches all pods within those namespaces, this rule permits ingress from any pod in any namespace, violating the intended restriction to only the policy's own namespace. This is a common mistake when trying to select 'all pods' without realizing the namespaceSelector broadens the selection globally.

  • ✗

    from: - ipBlock: cidr: 0.0.0.0/0

    Why it's wrong here

    An ipBlock rule with cidr 0.0.0.0/0 allows ingress from every IPv4 address, including sources outside the cluster entirely. This bypasses the pod-based identity model of NetworkPolicies, as it filters on raw IP addresses rather than Kubernetes labels or namespaces. Since the goal is to permit only traffic from pods in the same namespace, this rule is far too permissive and also fails to enforce any namespace or pod association.

  • ✓

    from: - podSelector: {}

    Why this is correct

    An empty podSelector with no namespaceSelector correctly limits the source to pods in the same namespace as the NetworkPolicy. In Kubernetes NetworkPolicy semantics, when only podSelector is specified, it implicitly selects pods within the policy's own namespace and does not affect other namespaces. Therefore, this rule allows ingress from all pods in that namespace while blocking traffic from other namespaces and external sources, matching the requirement precisely.

  • ✗

    from: - namespaceSelector: matchLabels: name: mynamespace

    Why it's wrong here

    This namespaceSelector targets a namespace labeled 'name: mynamespace', but it does not guarantee that the selected namespace is the same as the one where the policy is applied. If the policy's namespace lacks that label, or if another namespace carries the same label, traffic from that other namespace will be allowed, which may violate the intended same-namespace-only rule. Additionally, this rule selects all pods in the labeled namespace, not just the policy's own namespace, making it both namespace-external and overly broad.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.