CKAD Practice Question: Application Environment, Configuration and Security
Which TWO resources are used to enforce resource quotas at the namespace level? (Select TWO.)
⚠ Common exam trap
CNCF often tests the distinction between cluster-level and namespace-level resource controls, and the trap here is that candidates confuse HorizontalPodAutoscaler (which scales pods) with ResourceQuota (which caps total usage), or think NetworkPolicy enforces resource limits due to its 'policy' name.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ResourceQuota
ResourceQuota (C) is correct because it is the Kubernetes object that enforces aggregate quotas on a namespace, capping total CPU/memory requests and limits, pod counts, and object counts such as services, secrets, and PVCs. LimitRange (E) is correct because it enforces per-container or per-pod defaults and min/max constraints within a namespace, ensuring individual workloads cannot exceed or bypass the namespace's quota boundaries. HorizontalPodAutoscaler (A) only scales replica counts based on metrics and does not enforce quotas. NetworkPolicy (B) governs pod-level ingress/egress traffic rules, not resource consumption. PodDisruptionBudget (D) limits voluntary disruptions to maintain availability, not resource usage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HorizontalPodAutoscaler
Why it's wrong here
HorizontalPodAutoscaler (HPA) automatically scales the number of pod replicas in a Deployment, ReplicaSet, or StatefulSet based on observed CPU/memory usage or custom metrics. It reacts to demand by adjusting the replica count, but it does not impose any administrative limit on the total resources a namespace or its workloads can consume. Because HPA only manages scaling, not admission control, it cannot enforce resource quotas.
- ✗
NetworkPolicy
Why it's wrong here
NetworkPolicy is a Kubernetes object that defines ingress and egress rules for pods, restricting which sources can communicate with selected pods and which destinations those pods can access. It operates at the network layer (L3/L4, optionally L7) and has no bearing on CPU, memory, storage, or object counts. Since it only governs network traffic, it cannot be used to enforce resource quotas.
- ✓
ResourceQuota
Why this is correct
ResourceQuota is a namespace-scoped admission control object that sets aggregate limits on compute resources (e.g., cpu, memory) and on the number of certain objects (e.g., pods, services, PVCs) that can be created within that namespace. When any creation or update would exceed the quota, the API server rejects it with a 403 Forbidden, preventing resource exhaustion. This makes ResourceQuota one of the two core tools for enforcing namespace-level resource quotas.
- ✗
PodDisruptionBudget
Why it's wrong here
A PodDisruptionBudget (PDB) specifies the minimum number or percentage of pods that must remain available during voluntary disruptions, such as node drains, cluster upgrades, or deliberate evictions. It protects application availability during maintenance operations but does not limit how many resources can be consumed by a namespace or its workloads. PDBs only constrain when pods can be evicted, so they are entirely unrelated to resource quota enforcement.
- ✓
LimitRange
Why this is correct
LimitRange is a policy object that enforces minimum, maximum, and default resource requests/limits for individual pods, containers, or other resource types within a namespace. It works alongside ResourceQuota by providing per-workload constraints and default values, ensuring no single pod or container consumes an unreasonable share. Whereas ResourceQuota governs aggregate usage, LimitRange scopes resources at the individual workload level, making both necessary for comprehensive quota enforcement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.