Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

Match each Kubernetes network security concept to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Outbound network traffic from a pod to external endpoints

Inbound network traffic to a pod from external sources

Specification of how groups of pods are allowed to communicate

Container Network Interface plugin that implements networking for pods

Infrastructure layer for handling service-to-service communication, often with mTLS

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NetworkPolicy: A Kubernetes resource that defines rules for ingress and egress traffic to and from pods.

Correct matches: NetworkPolicy defines ingress/egress rules; Calico network policy extends with advanced features; Ingress rule controls inbound traffic; Egress rule controls outbound traffic; Default deny blocks all unless allowed. Common confusions include swapping ingress and egress definitions and mistaking non-native policies as native.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    NetworkPolicy: A Kubernetes resource that defines rules for ingress and egress traffic to and from pods.

    Why this is correct

    A Kubernetes NetworkPolicy is a namespaced API resource that uses label selectors to choose pods and then applies ordered rules to govern pod-level ingress and egress traffic. It operates at layer 3/4, matching on pod labels, namespaces, IP blocks, and ports, but it only takes effect when a CNI plugin implements the NetworkPolicy API. Without a companion default-deny policy, pods not selected by any NetworkPolicy remain fully open to all traffic.

  • ✓

    Calico network policy: A policy implemented by Calico that supports advanced features like IP blocks and service account selectors.

    Why this is correct

    Calico network policies are custom resource definitions (CRDs) introduced by the Calico CNI plugin, making them an extension to Kubernetes rather than a built-in object. They go beyond the standard NetworkPolicy model by supporting match criteria such as source/destination IP blocks, service account identities, and namespace selectors, and they add policy tiers for precedence control. This lets you segment workloads by identity or cluster topology, which vanilla NetworkPolicy cannot express.

  • ✓

    Ingress rule: In a NetworkPolicy, specifies which incoming traffic is allowed to reach pods.

    Why this is correct

    An ingress rule is the portion of a NetworkPolicy that defines which inbound connections are permitted to the selected pods. It explicitly lists sources—pods via selectors, namespaces, or IP/CIDR blocks—along with allowed ports and protocols, and it applies to traffic arriving at the pod's network interface. If any ingress rule is present, only traffic matching that rule is allowed (unless another policy also permits it), making it an allowlist for inbound traffic.

  • ✗

    Egress rule: In a NetworkPolicy, specifies which incoming traffic is allowed to reach pods.

    Why it's wrong here

    This statement is false because egress rules govern outbound connections from pods, not inbound traffic. An egress rule in a NetworkPolicy specifies which destinations—pods, namespaces, or IP/CIDR blocks—and which ports the selected pods are permitted to reach when initiating connections. Incoming traffic is controlled by ingress rules; swapping the two is a common misunderstanding that can lead to accidental over-permissive or over-restrictive policies.

  • ✓

    Default deny: A policy that blocks all traffic unless explicitly permitted by another policy.

    Why this is correct

    A default deny policy is a NetworkPolicy that selects all pods in a namespace and contains no allow rules, thereby dropping all traffic that is not explicitly permitted by another policy. It typically includes both policyTypes Ingress and Egress with empty rules to enforce zero-trust segmentation. Because Kubernetes defaults to 'allow all' when no NetworkPolicy matches a pod, you must deliberately apply a default-deny policy to block traffic by default.

  • ✗

    Calico network policy: A Kubernetes native resource for network segmentation.

    Why it's wrong here

    This answer is incorrect because Calico network policies are not native Kubernetes resources; they are custom resources introduced by the Calico CNI plugin. Native Kubernetes network segmentation is achieved through the built-in NetworkPolicy API, which CNI plugins implement to enforce rules. Calico's custom policy resource depends on Calico being installed as the cluster's networking solution or at least having its CRDs registered, so it is not part of core Kubernetes.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.