Courseiva
Services and Networking →hardMultiple Select

CKAD Services and Networking Practice Question

Which THREE of the following are valid fields in a NetworkPolicy spec?

⚠ Common exam trap

In the CKAD exam, candidates often confuse top-level spec fields with nested rule fields, mistakenly selecting `namespaceSelector` or `ipBlock` as valid spec fields when they are only valid within `ingress` or `egress` rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

podSelector

`podSelector` is a required field in a NetworkPolicy spec that defines which pods the policy applies to, using standard Kubernetes label selectors. It must be present to target specific pods within a namespace, and if set to an empty selector (e.g., `{}`), it selects all pods in the namespace. The CKAD exam often tests the distinction between top-level spec fields and nested rule fields, so candidates mistakenly select `namespaceSelector` or `ipBlock` as valid spec fields when they are only valid within `ingress` or `egress` rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    podSelector

    Why this is correct

    podSelector is a required field in a NetworkPolicy's spec. It uses label selector semantics to identify the pods within the current namespace to which the policy applies. An empty podSelector (e.g., `podSelector: {}`) is valid and matches all pods in the namespace, enabling default-deny policies. Without this field, the NetworkPolicy would not know which workloads its ingress or egress rules govern, so it is mandatory.

  • ✓

    ingress

    Why this is correct

    ingress is a valid top-level field in a NetworkPolicy spec and contains a list of ingress rules. Each rule defines allowed inbound traffic by specifying `from` sources (podSelector, namespaceSelector, or ipBlock) and optional ports. If the `policyTypes` field includes Ingress, an absent or empty `ingress` list results in all inbound traffic being denied. This field directly encodes the allowed inbound connections, making it structurally correct at the spec level.

  • ✓

    policyTypes

    Why this is correct

    policyTypes is a valid spec field that explicitly declares whether a NetworkPolicy applies to Ingress, Egress, or both. It is a list of strings, with allowed values `Ingress` and `Egress`. When omitted, the default is determined by the presence of `ingress` or `egress` rules; however, explicitly setting `policyTypes` to include a type with no corresponding rules forces a deny-all behavior for that direction. This field is part of the top-level spec and is therefore valid.

  • ✗

    namespaceSelector

    Why it's wrong here

    namespaceSelector is not a valid top-level field in a NetworkPolicy spec. It appears only inside an ingress rule's `from` array or an egress rule's `to` array, where it selects source or destination namespaces by label. Attempting to declare `namespaceSelector` directly under `spec` violates the API schema and will be rejected. Its correct structural position is as a peer of `podSelector` and `ipBlock` within a rule's peer list.

  • ✗

    ipBlock

    Why it's wrong here

    ipBlock is not a valid top-level field in a NetworkPolicy spec. It is used inside the `from` or `to` arrays of an ingress/egress rule to specify a CIDR range of IP addresses allowed or denied as traffic sources or destinations. Like `namespaceSelector`, it is a nested peer within a rule, not a sibling of `podSelector` or `policyTypes` at the spec level. Including `ipBlock` directly under `spec` is a schema error, which is why it is incorrect here.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.