CKAD Services and Networking Practice Question
Which THREE of the following are valid fields in a NetworkPolicy spec?
⚠ Common exam trap
In the CKAD exam, candidates often confuse top-level spec fields with nested rule fields, mistakenly selecting `namespaceSelector` or `ipBlock` as valid spec fields when they are only valid within `ingress` or `egress` rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
podSelector
`podSelector` is a required field in a NetworkPolicy spec that defines which pods the policy applies to, using standard Kubernetes label selectors. It must be present to target specific pods within a namespace, and if set to an empty selector (e.g., `{}`), it selects all pods in the namespace. The CKAD exam often tests the distinction between top-level spec fields and nested rule fields, so candidates mistakenly select `namespaceSelector` or `ipBlock` as valid spec fields when they are only valid within `ingress` or `egress` rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
podSelector
Why this is correct
podSelector is a required field in a NetworkPolicy's spec. It uses label selector semantics to identify the pods within the current namespace to which the policy applies. An empty podSelector (e.g., `podSelector: {}`) is valid and matches all pods in the namespace, enabling default-deny policies. Without this field, the NetworkPolicy would not know which workloads its ingress or egress rules govern, so it is mandatory.
- ✓
ingress
Why this is correct
ingress is a valid top-level field in a NetworkPolicy spec and contains a list of ingress rules. Each rule defines allowed inbound traffic by specifying `from` sources (podSelector, namespaceSelector, or ipBlock) and optional ports. If the `policyTypes` field includes Ingress, an absent or empty `ingress` list results in all inbound traffic being denied. This field directly encodes the allowed inbound connections, making it structurally correct at the spec level.
- ✓
policyTypes
Why this is correct
policyTypes is a valid spec field that explicitly declares whether a NetworkPolicy applies to Ingress, Egress, or both. It is a list of strings, with allowed values `Ingress` and `Egress`. When omitted, the default is determined by the presence of `ingress` or `egress` rules; however, explicitly setting `policyTypes` to include a type with no corresponding rules forces a deny-all behavior for that direction. This field is part of the top-level spec and is therefore valid.
- ✗
namespaceSelector
Why it's wrong here
namespaceSelector is not a valid top-level field in a NetworkPolicy spec. It appears only inside an ingress rule's `from` array or an egress rule's `to` array, where it selects source or destination namespaces by label. Attempting to declare `namespaceSelector` directly under `spec` violates the API schema and will be rejected. Its correct structural position is as a peer of `podSelector` and `ipBlock` within a rule's peer list.
- ✗
ipBlock
Why it's wrong here
ipBlock is not a valid top-level field in a NetworkPolicy spec. It is used inside the `from` or `to` arrays of an ingress/egress rule to specify a CIDR range of IP addresses allowed or denied as traffic sources or destinations. Like `namespaceSelector`, it is a nested peer within a rule, not a sibling of `podSelector` or `policyTypes` at the spec level. Including `ipBlock` directly under `spec` is a schema error, which is why it is incorrect here.
Go deeper
Related to this question
Learn chapter
Ingress Controllers and Ingress Resources
Key term
Init Containers
Init Containers are specialized containers that run and complete before the main containers in a Kubernetes Pod start, used for setup tasks like initializing data or waiting for dependencies.
Key term
ServiceAccount
A ServiceAccount is a Kubernetes identity used by pods to authenticate and authorize API requests to the Kubernetes cluster.
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.