Courseiva
Services and Networking →hardMultiple Select

CKAD Services and Networking Practice Question

Which THREE are valid fields in a NetworkPolicy spec? (Choose three.)

⚠ Common exam trap

A common mistake in Kubernetes is to confuse top-level spec fields with nested subfields. Candidates often select `ports` or `ipBlock` as direct spec fields, but they are only valid within `ingress` or `egress` rules in a NetworkPolicy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

podSelector

`podSelector` is a required field in a NetworkPolicy spec that defines which pods the policy applies to, using standard Kubernetes label selectors. It must be present to target specific pods within a namespace, and an empty `podSelector` selects all pods in the namespace.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    podSelector

    Why this is correct

    podSelector is a required field under spec. It uses label selectors to identify the pods to which this NetworkPolicy applies. An empty podSelector ({} ) matches all pods in the namespace, making the policy namespace-wide. Without it, the API rejects the policy because the policy would have no selected workload.

  • ✓

    ingress

    Why this is correct

    ingress is a valid top-level field in a NetworkPolicy spec and contains a list of ingress rule objects. Each ingress rule can specify allowed source peers via from and optionally restrict traffic by ports. The rules are ORed together; if ingress is present and no rule matches, traffic is denied for the selected pods. This field directly controls inbound traffic permitted by the policy.

  • ✗

    ports

    Why it's wrong here

    ports is not a valid top-level field in the NetworkPolicy spec. Port definitions are nested inside individual ingress or egress rule objects, along with protocol (TCP, UDP, or SCTP) and port number or named port. Attempting to declare ports directly under spec will cause a schema validation error, because the API expects only podSelector, ingress, egress, and policyTypes at that level.

  • ✓

    policyTypes

    Why this is correct

    policyTypes is an optional but valid field in a NetworkPolicy spec, given as a list of values Ingress, Egress, or both. It explicitly tells the control plane which rule sections to enforce; if omitted, the default is based on whether ingress or egress rules exist in the policy. This field is important when a policy has an empty ingress or egress list to intentionally deny all traffic of that type.

  • ✗

    ipBlock

    Why it's wrong here

    ipBlock is not a top-level field under spec; it belongs inside the from array of an ingress rule or the to array of an egress rule. It selects peers by CIDR range, excepting IPs listed in except, and cannot be used alone at the policy root. Putting ipBlock directly under spec is invalid and would be rejected by the Kubernetes API server.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.