CKAD Services and Networking Practice Question
Which TWO statements about NetworkPolicy are correct? (Choose two.)
⚠ Common exam trap
The CKAD exam often tests the misconception that NetworkPolicy is cluster-scoped or that it applies to Services, and the trap here is confusing the default 'allow all' behavior with the 'deny all' behavior when no policy is present.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NetworkPolicy uses labels to select pods within a namespace
NetworkPolicy uses label selectors in its `spec.podSelector` field to identify which pods within a namespace the policy applies to. This allows fine-grained control over traffic to and from specific sets of pods based on their labels, without needing to reference pod names or IPs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
If no NetworkPolicy selects a pod, then that pod is isolated and traffic is denied
Why it's wrong here
The default Kubernetes behavior is permissive: if no NetworkPolicy selects a pod, all inbound and outbound traffic is permitted. A pod only becomes isolated when a NetworkPolicy explicitly selects it, at which point traffic not allowed by the policy is denied. This statement incorrectly assumes a default-deny model, but in the absence of a policy, the pod is not isolated at all.
- ✗
NetworkPolicy is only applicable to Services
Why it's wrong here
NetworkPolicy operates directly on pods identified by label selectors, not on Service objects. Services are Kubernetes resources that provide stable IPs and DNS names for a set of pods, but they do not sit in the network path; NetworkPolicy rules apply to the pod's network interface, regardless of whether a Service fronts it. Even if you write a rule that references a Service, the actual enforcement is against the back-end pods matched by the Service's selector.
- ✗
NetworkPolicy is a cluster-scoped resource
Why it's wrong here
NetworkPolicy is namespaced: it resides in a specific namespace and its podSelector can only match pods in that same namespace. Unlike cluster-scoped resources such as ClusterRole or PersistentVolume, a NetworkPolicy cannot span namespaces or select pods from another namespace. This per-namespace scope is essential for isolating applications and enforcing tenant security boundaries.
- ✓
NetworkPolicy uses labels to select pods within a namespace
Why this is correct
The podSelector field in a NetworkPolicy is a label selector, consistent with how other Kubernetes resources select groups of objects. By setting matchLabels or matchExpressions, you can target specific pods (e.g., app: db) or all pods if the selector is empty, giving you flexible, IP-independent grouping. This is the only way to specify which pods a policy governs, so every policy must leverage labels.
- ✓
NetworkPolicy can specify both ingress and egress rules
Why this is correct
A NetworkPolicy has separate ingress and egress rule lists, allowing it to control both directions of traffic independently. Each rule can define its own sources/destinations (pod selectors, namespaces, or CIDRs) and port sets, giving fine-grained control. This dual-direction capability is what enables patterns like restricting a database pod to accept only app-tier traffic while denying all outbound connections except to a specific backup endpoint.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.