CKAD Services and Networking Practice Question
Which THREE are valid fields in a NetworkPolicy spec? (Choose three.)
⚠ Common exam trap
A common mistake in Kubernetes is to confuse top-level spec fields with nested subfields. Candidates often select `ports` or `ipBlock` as direct spec fields, but they are only valid within `ingress` or `egress` rules in a NetworkPolicy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
podSelector
`podSelector` is a required field in a NetworkPolicy spec that defines which pods the policy applies to, using standard Kubernetes label selectors. It must be present to target specific pods within a namespace, and an empty `podSelector` selects all pods in the namespace.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
podSelector
Why this is correct
podSelector is a required field under spec. It uses label selectors to identify the pods to which this NetworkPolicy applies. An empty podSelector ({} ) matches all pods in the namespace, making the policy namespace-wide. Without it, the API rejects the policy because the policy would have no selected workload.
- ✓
ingress
Why this is correct
ingress is a valid top-level field in a NetworkPolicy spec and contains a list of ingress rule objects. Each ingress rule can specify allowed source peers via from and optionally restrict traffic by ports. The rules are ORed together; if ingress is present and no rule matches, traffic is denied for the selected pods. This field directly controls inbound traffic permitted by the policy.
- ✗
ports
Why it's wrong here
ports is not a valid top-level field in the NetworkPolicy spec. Port definitions are nested inside individual ingress or egress rule objects, along with protocol (TCP, UDP, or SCTP) and port number or named port. Attempting to declare ports directly under spec will cause a schema validation error, because the API expects only podSelector, ingress, egress, and policyTypes at that level.
- ✓
policyTypes
Why this is correct
policyTypes is an optional but valid field in a NetworkPolicy spec, given as a list of values Ingress, Egress, or both. It explicitly tells the control plane which rule sections to enforce; if omitted, the default is based on whether ingress or egress rules exist in the policy. This field is important when a policy has an empty ingress or egress list to intentionally deny all traffic of that type.
- ✗
ipBlock
Why it's wrong here
ipBlock is not a top-level field under spec; it belongs inside the from array of an ingress rule or the to array of an egress rule. It selects peers by CIDR range, excepting IPs listed in except, and cannot be used alone at the policy root. Putting ipBlock directly under spec is invalid and would be rejected by the Kubernetes API server.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.