Courseiva
Services and Networking →hardMultiple Select

CKAD Services and Networking Practice Question

Which THREE of the following are true about NetworkPolicy? (Select 3)

⚠ Common exam trap

A common misconception is that NetworkPolicy is cluster-scoped or that it can control traffic to Services directly. In reality, NetworkPolicy only applies to Pod endpoints, not to the Service virtual IP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Multiple NetworkPolicies are additive

Kubernetes NetworkPolicy rules are additive: if multiple policies select the same pod, the effective network rules are the union of all rules from all policies. This means that if any policy allows ingress or egress traffic on a given port/protocol, that traffic is permitted, even if another policy does not explicitly allow it. This additive behavior is defined in the Kubernetes networking specification and is critical for correctly combining policies from different teams or layers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Multiple NetworkPolicies are additive

    Why this is correct

    NetworkPolicies are evaluated as a union: when multiple NetworkPolicy objects select the same pod, every rule from every selected policy is combined, and an allow rule in any one policy will permit that traffic even if another policy does not mention it. This means the effective policy is the sum of all allow rules, not an intersection. Traffic not explicitly allowed by any of the aggregated rules remains denied once isolation is triggered.

  • ✓

    NetworkPolicy can select pods in other namespaces using namespaceSelector

    Why this is correct

    A namespaceSelector in an ingress or egress rule can match pods that are running in other namespaces, because it selects namespaces by their labels rather than being restricted to the policy's own namespace. You can also combine a namespaceSelector with a podSelector to narrow the selection to specific pods inside those selected namespaces. This is how a NetworkPolicy in one namespace controls traffic to or from pods in different namespaces, even though the NetworkPolicy resource itself is namespaced.

  • ✗

    NetworkPolicy can control traffic to Services

    Why it's wrong here

    NetworkPolicy operates at the pod IP layer and cannot reference a Service resource by name or selector; it only sees pod-to-pod packets after kube-proxy has translated a Service ClusterIP to a backing pod's IP. Because Services are logical virtual IPs and DNS names, there is no way to write an allow rule for 'traffic to service my-svc' — the policy must target actual pods or namespaces. Therefore NetworkPolicy cannot directly control traffic to Services, although it indirectly affects Service-backed traffic by governing the pods behind that Service.

  • ✓

    If no NetworkPolicy selects a pod, then that pod is allowed all traffic

    Why this is correct

    In Kubernetes, the default state for pods is to accept all inbound and outbound traffic unless one or more NetworkPolicies select the pod. If no NetworkPolicy in the pod's namespace has a podSelector matching that pod, the pod is not isolated, so no policy rules restrict its communications. As soon as any NetworkPolicy selects the pod, the default changes to deny-unless-allowed, but absent that selection the allow-all behavior remains.

  • ✗

    NetworkPolicy is a cluster-scoped resource

    Why it's wrong here

    NetworkPolicy is a namespaced API resource — it lives in a single namespace, and its podSelector can only match pods within that same namespace. Because it cannot select pods across all namespaces at the cluster level, it does not have cluster scope like ClusterRole, ClusterRoleBinding, or Namespace objects do. This distinction is important because a NetworkPolicy must be created in the namespace where the target pods reside.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.