CKAD Services and Networking Practice Question
An administrator wants to allow ingress traffic to pods with label 'app: database' only from pods with label 'app: api' in the same namespace. Which NetworkPolicy rule is correct?
⚠ Common exam trap
A common mix-up: candidates confuse which podSelector applies to the target (the pods being protected) versus the source (the pods allowed to send traffic), leading them to reverse the labels as in Option B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
podSelector: { matchLabels: { app: database } } ingress: - from: - podSelector: { matchLabels: { app: api } }
It defines a NetworkPolicy that selects pods with label 'app: database' as the target (podSelector) and allows ingress traffic only from pods with label 'app: api' (ingress.from.podSelector). This matches the requirement exactly: only pods with 'app: api' can send traffic to pods with 'app: database' within the same namespace, as NetworkPolicy podSelector rules are namespace-scoped by default.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
podSelector: { matchLabels: { app: database } } ingress: - from: - ipBlock: { cidr: 10.0.0.0/8 }
Why it's wrong here
This NetworkPolicy selects database pods as the target, but the ingress source is an IP block (10.0.0.0/8), which matches by IP address rather than pod labels or namespace selectors. This permits any pod, node, or process within that CIDR range to reach the database, including workloads without the app:api label, and therefore fails to restrict access exclusively to the intended api pods. To enforce the requirement, the source must use a podSelector matching app:api, not an ipBlock.
- ✗
podSelector: { matchLabels: { app: api } } ingress: - from: - podSelector: { matchLabels: { app: database } }
Why it's wrong here
This policy is inverted relative to the requirement: it selects api pods as the target and allows traffic from database pods. The stated goal is to allow ingress to database pods from api pods, meaning the podSelector in the top-level spec should target app:database, while the from section should list app:api as the allowed source. Because the policy is attached to api pods, the database pods receive no ingress allowance from api pods, leaving the required traffic blocked.
- ✓
podSelector: { matchLabels: { app: database } } ingress: - from: - podSelector: { matchLabels: { app: api } }
Why this is correct
This is precisely what the administrator needs: the top-level podSelector targets the database pods, and the ingress rule's podSelector allows only traffic originating from pods with the app:api label. Since both selectors are in the same namespace and the from rule specifies a pod selector, the policy permits only api pods to reach the database, while all other sources remain denied by default (assuming a default-deny policy or as the only ingress rule on those pods). Thus, it matches the requirement exactly.
- ✗
podSelector: { matchLabels: { app: database } } ingress: - from: - namespaceSelector: { matchLabels: { name: default } }
Why it's wrong here
The target is correctly set to database pods, but the source is defined using a namespaceSelector for the 'default' namespace, which matches any pod in that namespace irrespective of its labels. This means any workload in default—including frontend, worker, or utility pods—can ingress to the database, not just the api pods specified in the requirement. To limit the source to api pods, you must use a podSelector (possibly in combination with a namespaceSelector if api pods live in another namespace), not a namespaceSelector alone.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.