CKAD Services and Networking Practice Question
You have a NetworkPolicy named 'deny-all' in namespace 'secure' that selects all pods and has no ingress rules. You need to allow incoming traffic to pods with label 'app: db' on port 5432 from pods with label 'app: api' in the same namespace. Which NetworkPolicy should you create?
⚠ Common exam trap
The trap here is applying the NetworkPolicy to the source pods instead of the destination pods; ingress rules must be on the pods receiving the traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A NetworkPolicy with podSelector matching 'app: db' and ingress rule allowing from podSelector 'app: api' on port 5432.
NetworkPolicies are additive, and a deny-all policy blocks all ingress unless explicitly allowed. To allow specific traffic, you must create a policy that selects the target pods ('app: db') and defines an ingress rule that matches the source pods ('app: api') on the correct port. Policies that control egress on the source, allow all IPs, or allow the entire namespace do not meet the precise restriction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A NetworkPolicy with podSelector matching 'app: db' and ingress rule allowing from namespaceSelector matching 'secure' on port 5432.
Why it's wrong here
This allows traffic from any pod in the 'secure' namespace, not specifically from pods with label 'app: api'. It is broader than necessary and would permit other pods in the namespace to connect. The requirement is to restrict to 'api' pods only, so this policy is too permissive and incorrect.
- ✓
A NetworkPolicy with podSelector matching 'app: db' and ingress rule allowing from podSelector 'app: api' on port 5432.
Why this is correct
This policy selects the target pods (app: db) and defines an ingress rule that allows traffic from pods with label app: api on TCP port 5432. Since NetworkPolicies are additive, this will allow the specified traffic while the deny-all policy continues to block everything else. It correctly implements the least privilege requirement.
- ✗
A NetworkPolicy with podSelector matching 'app: db' and ingress rule allowing from ipBlock 0.0.0.0/0 on port 5432.
Why it's wrong here
Allowing from all IPs (0.0.0.0/0) would permit traffic from any source, not just the 'api' pods. This violates the requirement to restrict access to only pods with label 'app: api'. It is overly permissive and does not meet the security objective. Thus, it is incorrect.
- ✗
A NetworkPolicy with podSelector matching 'app: api' and egress rule allowing to podSelector 'app: db' on port 5432.
Why it's wrong here
This policy controls egress traffic from the 'api' pods, not ingress to the 'db' pods. The deny-all policy blocks ingress to 'db' pods, so even if egress is allowed, the ingress would still be denied. To permit traffic, you must allow ingress on the destination pods. Therefore, this does not achieve the goal.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.