Courseiva
Services and Networking →mediumMultiple Choice

CKAD Services and Networking Practice Question

You want to block all ingress traffic to pods labeled 'app=api' except from pods labeled 'app=frontend'. Which NetworkPolicy rule is correct?

⚠ Common exam trap

It's easy for candidates to confuse podSelector with namespaceSelector, thinking namespaceSelector can filter by pod labels, when in fact podSelector is required to match pods by their labels within the same namespace.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ingress: - from: - podSelector: matchLabels: app: frontend

A NetworkPolicy with an ingress rule using a podSelector with matchLabels: app: frontend allows traffic only from pods that have that label. By default, when no NetworkPolicy selects the pods, all ingress traffic is allowed; once a policy selects them, only explicitly allowed traffic is permitted. This rule therefore blocks all ingress except from pods labeled app=frontend.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ingress: - from: - podSelector: matchLabels: app: frontend

    Why this is correct

    This rule is correct because it creates an ingress allow rule whose source is limited to pods that carry the label app=frontend. In a NetworkPolicy, any podSelector in a from element selects source pods in the policy's namespace, so traffic from all other pods is not explicitly allowed and will be blocked once this policy exists (default deny). Thus it satisfies the requirement to block all ingress to pods labeled app=a except from frontend pods.

  • ✗

    ingress: - from: - namespaceSelector: matchLabels: app: frontend

    Why it's wrong here

    This rule is wrong because namespaceSelector matches labels on namespaces, not on pods, so it would permit ingress from every pod running in any namespace labeled app=frontend. It does not narrow the source to the actual frontend pods; instead it grants broad access based on an administrative grouping, and it would still allow unintended pods within those namespaces to reach app=a.

  • ✗

    ingress: - ports: - port: 80

    Why it's wrong here

    This rule is wrong because a ports field only constrains the destination port of allowed traffic; it does not define which sources are permitted. With no from element, the rule allows traffic from all IP addresses to port 80 on the selected pods, so it actually expands ingress rather than blocking it. To block all except frontend pods, you must specify a source selector, not just port 80.

  • ✗

    ingress: - from: - ipBlock: cidr: 10.0.0.0/8

    Why it's wrong here

    This rule is wrong because ipBlock selects source addresses by CIDR range, not by pod labels, so it would permit any client in the 10.0.0.0/8 range to reach the pods labeled app=a. It ignores the identity of the frontend pods entirely and would allow traffic from arbitrary workloads or external IPs that happen to fall inside that block. A label-based selector is required to enforce the exact allow-from-frontend requirement.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.