CKAD Services and Networking Practice Question
Given the following NetworkPolicy YAML:
apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: deny-all spec: podSelector: {} policyTypes: - Ingress - Egress
What is the effect of this policy?
⚠ Common exam trap
Many candidates think an empty `podSelector: {}` with no rules means 'no policy' or 'allow all', but in Kubernetes, a NetworkPolicy with an empty rules list defaults to deny, not allow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Denies all ingress and egress traffic to and from all pods in the namespace
This NetworkPolicy uses an empty `podSelector: {}` which selects all pods in the namespace. By specifying both `Ingress` and `Egress` in `policyTypes` without any `ingress` or `egress` rules, the policy defaults to denying all ingress and egress traffic. In Kubernetes, NetworkPolicy rules are additive (allow-listed), so an empty rules list means no traffic is permitted, effectively creating a default-deny for both directions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Denies all ingress and egress traffic to and from all pods in the namespace
Why this is correct
This NetworkPolicy explicitly sets both policyTypes (Ingress and Egress) but includes no allow rules. In Kubernetes, an empty rules list for a given policyType creates a default-deny for that direction, so all inbound and outbound traffic is blocked. Since the policy's podSelector matches every pod in the namespace, it establishes a complete default-deny boundary for the entire namespace.
- ✗
Denies all ingress traffic but allows all egress traffic
Why it's wrong here
This answer confuses the behavior of a policy that specifies only Ingress with one that specifies both policyTypes. Because the policy declares both Ingress and Egress, it governs traffic in both directions, and an empty egress rule list does not permit outbound traffic — it denies it. The absence of egress rules means no outbound flows are allowed, contrary to the claim that egress remains open.
- ✗
Allows all traffic to and from pods in the namespace
Why it's wrong here
This option misunderstands the allow-list semantics of NetworkPolicy. In a namespace with no policies, traffic is allowed by default, but once a policy selects a pod, only explicitly permitted traffic is allowed and all other traffic is denied. Since this policy defines zero rules while selecting all pods, it permits nothing — effectively blocking all ingress and egress, rather than allowing it.
- ✗
Denies all traffic except traffic that is explicitly allowed by other policies
Why it's wrong here
This policy itself does not create an exception for traffic allowed by other policies; it simply has no allow rules, and with both policyTypes set, that yields a default-deny for both directions. Other policies selecting the same pods can independently add allow rules, and the Kubernetes API merges all rules as a union, so traffic permitted by any policy is allowed. The option wrongly implies this policy carves out a special allowance for other policies' rules, but in truth the effective allow-set is just the aggregate of every policy's rules, with no explicit exception mechanism.
Visual reference
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.