mediumMultiple Choice
CKS Practice Question: After a security incident, you need to restrict…
After a security incident, you need to restrict which pods can communicate with each other in the 'finance' namespace. You want to allow only pods with label 'app: api' to connect to pods with label 'app: db' on TCP port 5432, and deny all other traffic. Which NetworkPolicy should you create?
⚠ Common exam trap
CNCF often tests the direction of traffic flow: candidates mistakenly apply the policy to the source pod (app: api) with an ingress rule, which would control traffic coming into the api pod rather than traffic going to the db pod, or they forget to specify the port, allowing all ports from the allowed source.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-api-to-db namespace: finance spec: podSelector: matchLabels: app: db ingress: - from: - podSelector: matchLabels: app: api ports: - port: 5432
It defines a NetworkPolicy that selects pods with label 'app: db' as the target and allows ingress traffic only from pods with label 'app: api' on TCP port 5432. By default, if no NetworkPolicy exists, all traffic is allowed; once a NetworkPolicy selects a pod, all traffic not explicitly allowed is denied. This policy therefore restricts communication to only the intended api-to-db flow on the specified port.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-api-to-db namespace: finance spec: podSelector: matchLabels: app: api ingress: - from: - podSelector: matchLabels: app: db ports: - port: 5432
Why it's wrong here
This NetworkPolicy selects pods with label app: api, so the ingress rule applies to the API pods, not the database pods. As a result, the policy allows connections from db pods to the API on port 5432 — the reverse of the intended direction. It places no restriction on incoming traffic to the database, leaving the DB exposed to all other pods. To control access to the database, the podSelector must target the DB pods (app: db).
- ✗
apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-api-to-db namespace: finance spec: podSelector: matchLabels: app: api egress: - to: - podSelector: matchLabels: app: db ports: - port: 5432
Why it's wrong here
This policy defines an egress rule on the API pods, allowing them to initiate connections to the database on port 5432. While it permits the desired flow, it does not govern ingress to the database; any pod can still reach the DB unless a separate NetworkPolicy selects the DB pods and denies other traffic. Egress policies on a source do not create a default deny for the destination. A realistic fix requires an ingress policy on the DB pods that explicitly permits traffic from the API on the correct port.
- ✗
apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-api-to-db namespace: finance spec: podSelector: matchLabels: app: db ingress: - from: - podSelector: matchLabels: app: api
Why it's wrong here
Here the podSelector correctly targets the database pods, but the ingress rule from the API pods omits the port field. In a NetworkPolicy rule, an empty ports list matches all ports and protocols, so this would allow API pods to reach any port on the database, not just 5432. That is far broader than the stated requirement and could expose other database services. The rule should include ports: - port: 5432 to limit the permitted traffic to the database's PostgreSQL listener.
- ✓
apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-api-to-db namespace: finance spec: podSelector: matchLabels: app: db ingress: - from: - podSelector: matchLabels: app: api ports: - port: 5432
Why this is correct
This is the correct policy. It selects the DB pods and applies an ingress rule that allows only traffic from pods with label app: api on TCP port 5432. The presence of any NetworkPolicy selecting a pod makes that pod default-deny for ingress, so all other sources and ports are implicitly blocked. This matches the requirement: only the API can reach the database on the PostgreSQL port, and everything else is denied. The port restriction and podSelector together create a precise allow-list for the database.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.