Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

During a security incident, you need to isolate a compromised pod named 'malicious-pod' in namespace 'default' to prevent it from communicating with other pods. Which command should you run?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl apply -f networkpolicy.yaml

Pod isolation is achieved by applying a NetworkPolicy that denies ingress/egress traffic. 'kubectl apply -f networkpolicy.yaml' applies the policy. The policy must be written to deny all traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl run networkpolicy --image=nginx --restart=Never

    Why it's wrong here

    This command invokes kubectl run, which creates a workload object (a standalone Pod) named 'networkpolicy' using the nginx image, not any kind of isolation rule. NetworkPolicy is a distinct networking.k8s.io/v1 API resource and cannot be created via kubectl run; this command would merely deploy an extra container, leaving the malicious pod's network paths completely unrestricted, so it fails to quarantine the compromise.

  • ✗

    kubectl delete pod malicious-pod

    Why it's wrong here

    Deleting the pod is a destructive action that neither denies traffic nor blocks lateral movement; if the pod is managed by a Deployment, ReplicaSet, or StatefulSet, the controller will immediately recreate it with the same labels, nullifying the action. Even if it is not recreated, the pod is unavailable for forensic analysis, whereas a NetworkPolicy isolates the pod in place by dropping ingress/egress traffic, preserving running processes and memory for investigation. Also, deletion only removes this one instance—network isolation via policy protects against compromised replicas or other pods with the same labels.

  • ✓

    kubectl apply -f networkpolicy.yaml

    Why this is correct

    Applying a NetworkPolicy YAML is the correct method because this API resource is designed to select pods by label and restrict their ingress and egress traffic. A properly written manifest with a podSelector matching 'app=malicious' and policyTypes: [Ingress, Egress] but no ingress/egress rules creates a default-deny rule for that pod, blocking all inbound and outbound connections non-destructively. kubectl apply is also idempotent and the only reliable way to declare such a policy, since kubectl does not offer a native 'create networkpolicy' command.

  • ✗

    kubectl create networkpolicy isolate --pod-selector=app=malicious --policy-types=Ingress,Egress

    Why it's wrong here

    This command is invalid because kubectl create has no 'networkpolicy' subresource—the only supported object types are resources like deployment, job, namespace, service, and serviceaccount. Even with the claimed flags, kubectl would reject the invocation with an error, and no isolation rule would be applied. NetworkPolicy resources must be supplied as YAML (e.g., kubectl apply -f), so this attempt is a non-starter for quarantining the compromised pod.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.