Courseiva
Services and Networking →hardMultiple Choice

CKAD Services and Networking Practice Question

You have a NetworkPolicy named 'deny-all' in namespace 'secure' that selects all pods and has no ingress rules. You need to allow incoming traffic to pods with label 'app: db' on port 5432 from pods with label 'app: api' in the same namespace. Which NetworkPolicy should you create?

⚠ Common exam trap

The trap here is applying the NetworkPolicy to the source pods instead of the destination pods; ingress rules must be on the pods receiving the traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A NetworkPolicy with podSelector matching 'app: db' and ingress rule allowing from podSelector 'app: api' on port 5432.

NetworkPolicies are additive, and a deny-all policy blocks all ingress unless explicitly allowed. To allow specific traffic, you must create a policy that selects the target pods ('app: db') and defines an ingress rule that matches the source pods ('app: api') on the correct port. Policies that control egress on the source, allow all IPs, or allow the entire namespace do not meet the precise restriction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A NetworkPolicy with podSelector matching 'app: db' and ingress rule allowing from namespaceSelector matching 'secure' on port 5432.

    Why it's wrong here

    This allows traffic from any pod in the 'secure' namespace, not specifically from pods with label 'app: api'. It is broader than necessary and would permit other pods in the namespace to connect. The requirement is to restrict to 'api' pods only, so this policy is too permissive and incorrect.

  • ✓

    A NetworkPolicy with podSelector matching 'app: db' and ingress rule allowing from podSelector 'app: api' on port 5432.

    Why this is correct

    This policy selects the target pods (app: db) and defines an ingress rule that allows traffic from pods with label app: api on TCP port 5432. Since NetworkPolicies are additive, this will allow the specified traffic while the deny-all policy continues to block everything else. It correctly implements the least privilege requirement.

  • ✗

    A NetworkPolicy with podSelector matching 'app: db' and ingress rule allowing from ipBlock 0.0.0.0/0 on port 5432.

    Why it's wrong here

    Allowing from all IPs (0.0.0.0/0) would permit traffic from any source, not just the 'api' pods. This violates the requirement to restrict access to only pods with label 'app: api'. It is overly permissive and does not meet the security objective. Thus, it is incorrect.

  • ✗

    A NetworkPolicy with podSelector matching 'app: api' and egress rule allowing to podSelector 'app: db' on port 5432.

    Why it's wrong here

    This policy controls egress traffic from the 'api' pods, not ingress to the 'db' pods. The deny-all policy blocks ingress to 'db' pods, so even if egress is allowed, the ingress would still be denied. To permit traffic, you must allow ingress on the destination pods. Therefore, this does not achieve the goal.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.