Courseiva

CKS NetworkPolicy Practice Question

In Kubernetes, you need to enforce a default deny-all network policy for pods in a specific namespace to ensure pods cannot communicate unless explicitly allowed by policy. Which resource should you create?

⚠ Common exam trap

Candidates often confuse namespace-scoped controls: ResourceQuota and LimitRange limit resource consumption, while NetworkPolicy is the only one of these that enforces pod-to-pod network segmentation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NetworkPolicy

A NetworkPolicy is the Kubernetes resource that controls network traffic to and from pods. A default deny-all policy can be created by selecting all pods (e.g., using an empty podSelector) and omitting ingress/egress rules. ResourceQuota and LimitRange manage compute/resource usage, not network traffic, and RuntimeClass selects a container runtime configuration rather than enforcing network policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    NetworkPolicy

    Why this is correct

    A NetworkPolicy with an empty pod selector and both Ingress and Egress policyTypes set to deny enforces default deny-all for every pod in the namespace, satisfying the requirement that communication is blocked unless explicitly permitted. Kubernetes' native policy object operates at layer 3/4, matching the namespace-scoped constraint in the stem.

  • ✗

    ResourceQuota

    Why it's wrong here

    ResourceQuota caps aggregate namespace consumption of CPU, memory, object counts and storage; it never evaluates pod selectors or traffic direction. It is tempting because it is a namespace-scoped admission control, and would be correct when you must limit total resource usage across a namespace.

  • ✗

    LimitRange

    Why it's wrong here

    LimitRange sets per-pod or per-container CPU, memory and storage defaults and limits within a namespace; it does not select pods or define ingress/egress rules. It is tempting because it also governs namespace-level pod behaviour, and would be correct when you need to constrain resource requests.

  • ✗

    RuntimeClass

    Why it's wrong here

    RuntimeClass selects which container runtime configuration (for example gVisor or Kata) a pod uses; it has no network policy semantics. It is tempting as another pod-level isolation mechanism, and would be correct when you need stronger workload sandboxing rather than traffic denial.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.