CKAD Services and Networking Practice Question
You apply the following NetworkPolicy:
apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: deny-all spec: podSelector: {} policyTypes: - Ingress - Egress
After applying, pods in the namespace cannot reach the kube-dns service. What is the most likely reason?
⚠ Common exam trap
Candidates often assume a NetworkPolicy with no rules allows all traffic, but in Kubernetes, an empty `podSelector: {}` combined with `policyTypes` that list a direction (Ingress/Egress) actually defaults to denying all traffic in that direction, which is the opposite of what many expect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy blocks all egress traffic, including DNS
The NetworkPolicy explicitly includes `Egress` in `policyTypes` and uses an empty `podSelector: {}`, which selects all pods in the namespace. With no `egress` rules defined, the default behavior is to deny all egress traffic. DNS resolution for kube-dns typically uses UDP/TCP on port 53, and since all egress traffic is blocked, pods cannot reach the kube-dns service, causing DNS failures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy does not have a namespaceSelector
Why it's wrong here
The absence of a namespaceSelector is not the cause of the connectivity issue. A NetworkPolicy applies to the namespace in which it is created, and an empty podSelector (`podSelector: {}`) selects all pods in that namespace, so a namespaceSelector is unnecessary to make the policy effective. The policy already matches every pod in its own namespace, so DNS traffic is indeed affected by the egress rules.
- ✓
The policy blocks all egress traffic, including DNS
Why this is correct
The policy defines no egress rules (an empty `egress` list), which by NetworkPolicy semantics means all egress traffic is denied — including DNS queries sent over UDP port 53 to the kube-dns service. Even if other services are reachable within the cluster, the inability to resolve DNS names will cause most network communication to fail, making this the primary reason the pod cannot connect. Ingress is also blocked, but the DNS failure is exclusively an egress-side issue.
- ✗
The policy blocks all ingress traffic only
Why it's wrong here
The policy does not only block ingress; it also blocks egress because the `egress` field is present but empty. In Kubernetes NetworkPolicy, an empty `egress` list results in a default-deny for all outbound traffic, and an empty `ingress` list similarly denies inbound traffic. Therefore, the pod cannot send DNS queries or any other outbound packets, which explains the DNS failure more directly than simply saying ingress is blocked.
- ✗
The kube-dns service is not running
Why it's wrong here
The kube-dns service is almost certainly running; the real cause is the NetworkPolicy blocking the pod's egress to port 53. If kube-dns were down, pods that are not subject to any policy would also experience DNS failures, but here the issue is isolated to the namespace or pods affected by the policy. Since the policy explicitly denies all egress, the DNS request never reaches the kube-dns service, so the service's availability is irrelevant to this failure.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.