CKAD Services and Networking Practice Question
Which of the following is a valid NetworkPolicy that allows ingress traffic only from pods with label 'role: frontend' in any namespace?
⚠ Common exam trap
The trap here is that candidates often forget that a `podSelector` without a `namespaceSelector` only applies to the same namespace, and they may incorrectly choose option C, not realizing that the question explicitly requires traffic from 'any namespace'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ingress: - from: - namespaceSelector: {} podSelector: matchLabels: role: frontend
It uses a `namespaceSelector: {}` (which matches all namespaces) combined with a `podSelector` that selects pods with label `role: frontend`. This combination allows ingress traffic from pods with that label in any namespace, which is exactly what the question requires. In Kubernetes NetworkPolicy, when you want to select pods across all namespaces, you must include an empty `namespaceSelector` alongside the `podSelector`.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ingress: - from: - namespaceSelector: {} podSelector: matchLabels: role: frontend
Why this is correct
The empty namespaceSelector {} acts as a wildcard that selects all namespaces in the cluster, and the podSelector restricts the rule to only pods labeled role: frontend. Because the namespace selector and pod selector are both present in a single from entry, they are combined with an AND: allowed sources are frontend pods in any namespace. This correctly implements the requirement to allow only frontend pods across all namespaces, rather than limiting them to the policy's own namespace.
- ✗
ingress: - from: - ipBlock: cidr: 0.0.0.0/0
Why it's wrong here
An ipBlock rule with cidr 0.0.0.0/0 matches every IPv4 address, including all pods, nodes, and external clients, regardless of any pod labels. Since the requirement is to allow only frontend pods, this rule is far too broad and would permit ingress from any source. Unlike podSelector, an ipBlock cannot be scoped by pod or namespace labels, so it cannot express the intended restriction.
- ✗
ingress: - from: - podSelector: matchLabels: role: frontend
Why it's wrong here
Without a namespaceSelector, a podSelector in a NetworkPolicy applies only to pods in the same namespace as the policy object itself. Thus this rule would allow ingress only from frontend pods located in that one namespace, not from frontend pods in other namespaces. If the intent is to allow frontend pods cluster-wide, you must also include an empty namespaceSelector to broaden the scope across all namespaces.
- ✗
ingress: - from: - namespaceSelector: matchLabels: role: frontend
Why it's wrong here
A namespaceSelector with matchLabels role: frontend selects whole namespaces that have that label, but it contains no podSelector to delineate which pods inside those namespaces are allowed. As a result, this rule would permit traffic from every pod in any namespace labeled role: frontend, not just pods that also have the role: frontend label. It therefore fails the requirement to restrict ingress to frontend pods specifically.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.