Courseiva
Services and Networking →mediumMultiple Choice

CKAD Services and Networking Practice Question

You need to create a NetworkPolicy that denies all ingress traffic to pods with label 'app: db' in namespace 'prod'. Which YAML snippet correctly implements this?

⚠ Common exam trap

Test-takers frequently confuse an empty ingress array (deny-all) with an empty from array (which also denies all but is often misapplied), or they forget to set the correct podSelector and namespace, leading to policies that either allow all traffic or apply to the wrong pods.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: deny-db namespace: prod spec: podSelector: matchLabels: app: db policyTypes: - Ingress ingress: []

It defines a NetworkPolicy that selects pods with label 'app: db' in namespace 'prod', specifies 'policyTypes: [Ingress]', and sets 'ingress: []'. An empty ingress rule list means no ingress traffic is allowed, effectively denying all ingress to the selected pods. This is the standard Kubernetes pattern for creating a deny-all ingress policy for a specific set of pods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: deny-db namespace: prod spec: podSelector: matchLabels: app: db policyTypes: - Ingress ingress: - from: - ipBlock: cidr: 0.0.0.0/0

    Why it's wrong here

    This policy targets the correct podSelector and namespace, but the ingress rule with ipBlock 0.0.0.0/0 explicitly permits all IPv4 traffic from any source. In NetworkPolicy semantics, any ingress rule — even a broad allow — overrides the default-deny behavior; since this rule matches every possible source address, it effectively allows all ingress to the selected pods instead of denying it. To deny all ingress, you must include no ingress rules at all (ingress: []), not a rule that matches everything.

  • ✗

    apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: deny-all namespace: prod spec: podSelector: {} policyTypes: - Ingress ingress: - from: []

    Why it's wrong here

    This manifest is invalid because the ingress field contains a rule with an empty from array. According to the NetworkPolicy API, an ingress rule with no from field (or empty from) means 'allowed from all sources' — it is an implicit allow-all rule, not a deny. Using from: [] inside a rule is not a way to express denial; it actually matches all peers, thereby permitting unrestricted ingress. To deny all ingress, the entire ingress array must be empty (ingress: []), not have an empty from list.

  • ✗

    apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: deny-all spec: podSelector: {} policyTypes: - Ingress ingress: []

    Why it's wrong here

    This policy has the correct empty ingress array, which would deny all ingress to the selected pods, but the podSelector {} selects every pod in the namespace where the policy is created. Critically, the manifest omits the namespace field, so the policy is created in the default namespace rather than 'prod'. Since NetworkPolicies are namespaced resources, this would not apply to the production database pods targeted by the question, making it ineffective for the stated requirement.

  • ✓

    apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: deny-db namespace: prod spec: podSelector: matchLabels: app: db policyTypes: - Ingress ingress: []

    Why this is correct

    This is the correct NetworkPolicy because it selects the intended pods via podSelector.matchLabels.app: db and restricts itself to the prod namespace with the namespace field. It declares policyTypes: [Ingress] and provides an empty ingress array ([]), which means no ingress rules are defined. With no allow rules, the policy defaults to denying all ingress traffic to the selected pods, satisfying the 'deny all ingress' requirement exactly as asked.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.