Courseiva
Services and Networking →hardMultiple Choice

CKAD Services and Networking Practice Question

A NetworkPolicy with the following spec is applied to a namespace. What is the effect? spec: podSelector: {} policyTypes: - Ingress - Egress ingress: - from: - ipBlock: cidr: 10.0.0.0/8 except: - 10.0.1.0/24 egress: - to: - ipBlock: cidr: 0.0.0.0/0

⚠ Common exam trap

The trap here is that candidates often forget that an empty podSelector selects all pods, and that listing a policyType without a matching rule defaults to deny, but a rule with 0.0.0.0/0 for egress explicitly allows all outbound traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deny all ingress traffic except from 10.0.0.0/8 excluding 10.0.1.0/24; allow all egress

The NetworkPolicy selects all pods in the namespace (empty podSelector matches all pods) and explicitly defines both Ingress and Egress policy types. The ingress rule allows traffic only from the 10.0.0.0/8 range, except 10.0.1.0/24, effectively denying all other ingress. The egress rule allows all outbound traffic to 0.0.0.0/0, so egress is unrestricted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deny all ingress and egress traffic

    Why it's wrong here

    This is incorrect because the policy contains no egress rule, so egress traffic is not denied; in the absence of an egress rule, the policyTypes defaults to only affect ingress, leaving egress fully allowed. Furthermore, the ingress rule does not deny all ingress—it explicitly permits traffic from the 10.0.0.0/8 block outside the excepted 10.0.1.0/24, so the 'deny all' characterization is inaccurate.

  • ✗

    Allow all ingress and egress traffic

    Why it's wrong here

    This option fails because the ingress rule is actively restrictive: it only matches source IPs within 10.0.0.0/8 while excluding 10.0.1.0/24, so traffic from any other IP is blocked. Egress may indeed remain allowed, but the policy does not allow all ingress, effectively creating a whitelist for a specific IP block rather than open access.

  • ✓

    Deny all ingress traffic except from 10.0.0.0/8 excluding 10.0.1.0/24; allow all egress

    Why this is correct

    This is accurate: the ingress rule uses an ipBlock with cidr 10.0.0.0/8 and except 10.0.1.0/24, which permits traffic from any address in the /8 range except that specific /24, and denies everything else by default isolation. Since no egress rule is defined and policyTypes only includes Ingress, egress traffic remains unrestricted, matching the 'allow all egress' clause.

  • ✗

    Allow ingress from 10.0.1.0/24 only

    Why it's wrong here

    This is inverted: the except clause specifically excludes 10.0.1.0/24, meaning that subnet is not allowed to reach pods, not that it is the sole allowed source. The policy's allowed source set is 10.0.0.0/8 minus 10.0.1.0/24, which is a much broader range, so saying 'only 10.0.1.0/24' directly contradicts the rule's logic.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.