You apply the following NetworkPolicy: apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: deny-all spec: podSelector: {} policyTypes: - Ingress - Egress After applying, pods in the namespace cannot reach the kube-dns service. What is the most likely reason?
The policy defines no egress rules (an empty `egress` list), which by NetworkPolicy semantics means all egress traffic is denied — including DNS queries sent over UDP port 53 to the kube-dns service. Even if other services are reachable within the cluster, the inability to resolve DNS names will cause most network communication to fail, making this the primary reason the pod cannot connect. Ingress is also blocked, but the DNS failure is exclusively an egress-side issue.
Why this answer
The NetworkPolicy explicitly includes `Egress` in `policyTypes` and uses an empty `podSelector: {}`, which selects all pods in the namespace. With no `egress` rules defined, the default behavior is to deny all egress traffic. DNS resolution for kube-dns typically uses UDP/TCP on port 53, and since all egress traffic is blocked, pods cannot reach the kube-dns service, causing DNS failures.
Exam trap
The trap here is that candidates often assume a NetworkPolicy with no rules allows all traffic, but in Kubernetes, an empty `podSelector: {}` combined with `policyTypes` that list a direction (Ingress/Egress) actually defaults to denying all traffic in that direction, which is the opposite of what many expect.
How to eliminate wrong answers
Option A is wrong because a `namespaceSelector` is not required for this policy; the `podSelector: {}` already selects all pods in the namespace, and the policy correctly applies to the namespace where it is created. Option C is wrong because the policy includes both `Ingress` and `Egress` in `policyTypes`, so it blocks both ingress and egress traffic, not just ingress. Option D is wrong because the question states that after applying the policy, pods cannot reach kube-dns, implying the service was running before; the issue is caused by the network policy, not the service's availability.