Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

A developer reports that a pod cannot reach an external database at 192.168.1.100:3306. The pod's namespace is 'app'. You need to create a NetworkPolicy that allows egress to that IP only. Which policy is correct?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-egress namespace: app spec: podSelector: {} egress: - to: - ipBlock: cidr: 192.168.1.100/32 ports: - port: 3306 protocol: TCP policyTypes: - Egress

The correct NetworkPolicy must allow egress traffic from pods in the 'app' namespace to the specific IP 192.168.1.100 on port 3306. Option D meets this requirement by using 'podSelector: {}' to apply to all pods, specifying an egress rule to the ipBlock with the correct CIDR and port 3306, and setting 'policyTypes: [Egress]'. Option A is missing the port specification, so it would allow egress to the IP on any port, which is too permissive. Option B uses 'matchLabels: app: myapp', restricting the policy to pods with that label, and also lacks the port. Option C defines an ingress rule instead of egress, which does not address the egress requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-egress namespace: app spec: podSelector: {} egress: - to: - ipBlock: cidr: 192.168.1.100/32 policyTypes: - Egress

    Why it's wrong here

    This egress rule targets all pods in the namespace and correctly uses ipBlock for the external database IP, but it omits the ports field. Without restricting to TCP/3306, the policy permits every destination port on that IP, which is broader than necessary and fails to demonstrate the precise least-privilege access required for the MySQL connection.

  • ✗

    apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-egress namespace: app spec: podSelector: matchLabels: app: myapp egress: - to: - ipBlock: cidr: 192.168.1.100/32 policyTypes: - Egress

    Why it's wrong here

    By setting podSelector to matchLabels: app: myapp, this policy only applies to pods carrying that exact label. The developer's pod is not guaranteed to have that label, so if the selector matches no pods the egress rule is a no-op and the original connectivity failure remains. A namespace-wide selector (podSelector: {}) would cover all pods, including the affected one.

  • ✗

    apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-egress namespace: app spec: podSelector: {} ingress: - from: - ipBlock: cidr: 192.168.1.100/32 policyTypes: - Ingress

    Why it's wrong here

    This NetworkPolicy defines an ingress rule, which filters traffic coming into the pods from the database IP, not traffic leaving the pods. Since the developer’s pod cannot initiate a connection to an external data source, the missing capability is egress. An ingress rule has no effect on outbound connectivity, so this policy does not address the reported problem.

  • ✓

    apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-egress namespace: app spec: podSelector: {} egress: - to: - ipBlock: cidr: 192.168.1.100/32 ports: - port: 3306 protocol: TCP policyTypes: - Egress

    Why this is correct

    This policy selects all pods in the namespace via podSelector: {} and permits egress traffic specifically to the database IP on TCP port 3306, which is the MySQL port mentioned in the scenario. By including both the destination IP and the exact port, it follows least privilege and directly restores the pod's ability to reach the external data source while blocking other outbound traffic.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.