Courseiva

CKS NetworkPolicy egress Practice Question

A pod named 'compromised-pod' is suspected of making unauthorized outbound connections. You want to isolate the pod using a NetworkPolicy. Which policy correctly denies all egress traffic from the pod?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NetworkPolicy with podSelector: matchLabels: app: compromised and egress: []

A NetworkPolicy with podSelector matching 'compromised-pod' (via label app=compromised) and an empty egress list (egress: []) explicitly denies all egress traffic from the pod. This is the standard Kubernetes pattern to isolate a pod by default-deny egress. Option A allows egress to 0.0.0.0/0, which permits all outbound traffic. Option B only restricts ingress, not egress. Option D allows egress to pods matching an empty podSelector (all pods), thus permitting traffic to other pods in the namespace. Therefore, only option C achieves complete egress isolation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    NetworkPolicy with podSelector: {} and egress: [{to: [{ipBlock: {cidr: 0.0.0.0/0}}]}]

    Why it's wrong here

    This policy selects every pod in the namespace via podSelector: {} and allows egress to 0.0.0.0/0, meaning any IPv4 destination. Because it whitelists all outbound traffic, it leaves the compromised pod free to continue unauthorized communication, and with policyTypes omitted, the policy defaults to only Egress, so Ingress is not even restricted. It fails to create any isolation and is the opposite of a deny-all egress rule.

  • ✗

    NetworkPolicy with podSelector: matchLabels: app: compromised and policyTypes: ["Ingress"]

    Why it's wrong here

    Here the podSelector targets only the compromised pod, but policyTypes is set to ['Ingress'], so the policy only governs inbound traffic. No egress rules are defined, and the default behavior for a pod with an Ingress-only policy is to leave egress completely unrestricted. Therefore, the compromised pod's ability to initiate outbound connections—the exact issue under investigation—remains untouched.

  • ✓

    NetworkPolicy with podSelector: matchLabels: app: compromised and egress: []

    Why this is correct

    This policy selects the compromised pod and specifies egress: [] as an empty list. An empty egress rule list is a deny-all: since no destinations are allowed, all outbound traffic from that pod is blocked. With an egress list present, policyTypes defaults to Egress, so this rule is enforced; any additional egress allowances must be added in separate policies, which are ORed. This provides immediate containment of the suspicious outbound activity.

  • ✗

    NetworkPolicy with podSelector: matchLabels: app: compromised and egress: [{to: [{podSelector: {}}]}]

    Why it's wrong here

    Though this policy correctly selects the compromised pod, its egress rule allows traffic to podSelector: {}, which matches every pod in the namespace. This permits lateral movement to any internal workload, so the pod can still reach other applications and potentially exfiltrate data or spread malware. It does deny external IP communication, but internal communication remains open, making it insufficient as an isolation control.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.