Courseiva
Cluster Hardening →easyMultiple Choice

CKS Cluster Hardening Practice Question

Which Kubernetes resource should be used to restrict egress traffic from pods?

⚠ Common exam trap

Candidates often confuse egress (outbound) with ingress (inbound) rules, or assume PodSecurityPolicy can restrict network traffic, when it only governs pod security contexts like privileged mode and host namespaces.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NetworkPolicy with egress rules

NetworkPolicy with egress rules is the correct Kubernetes-native resource to restrict outbound traffic from pods. It uses label selectors, IP blocks, and port specifications to define which external destinations pods can reach, enforcing zero-trust network segmentation at the pod level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    NetworkPolicy with egress rules

    Why this is correct

    NetworkPolicy with egress rules is the Kubernetes-native resource for restricting outbound traffic. An egress rule can select target pods via podSelector, namespaceSelector, or CIDR blocks, and also specify allowed ports. This provides API-declarative, label-based access control at L3/L4, enforced by the CNI plugin (e.g., Calico, Cilium). Since NetworkPolicy is a namespaced resource scoped to pods, it is the correct and supported mechanism to directly limit egress within a cluster.

  • ✗

    PodSecurityPolicy

    Why it's wrong here

    PodSecurityPolicy (PSP) is an admission controller that governs pod security contexts — such as privilege escalation, host namespaces, or Linux capabilities. It never touches network packets or low-level traffic routing, so it has no mechanism to block outbound connections. The resource is deprecated and removed in Kubernetes 1.25, and it was never a network policy object. Thus, using PSP to restrict egress is conceptually invalid and technically impossible.

  • ✗

    iptables rules on nodes

    Why it's wrong here

    iptables rules placed on nodes are not a Kubernetes resource; they are operating-system-level firewall entries managed via iptables/ipvs on each host. While on the data path, they lack pod identity awareness and selectors, so many users implement them as static rules that cannot scale or adapt to dynamic pod IPs. Also, the Kubernetes API has no knowledge of these rules, which breaks declarative management and auditability. Therefore, they are an external tool, not a resource, and unsuitable for pod-specific egress control.

  • ✗

    NetworkPolicy with ingress rules

    Why it's wrong here

    NetworkPolicy with ingress rules restricts only incoming traffic to the selected pods. Although the policy object shares the same schema, an ingress rule has no effect on outbound sessions initiated by pods; egress traffic will still be routed as per the cluster defaults. To control traffic leaving a pod, you must explicitly add an egress section (or use policyTypes: ['Egress']). Thus, ingress rules alone cannot limit egress and are the inverse of the required direction.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.