CKS Monitoring, Logging and Runtime Security Practice Question
You need to configure a NetworkPolicy that allows egress traffic only to an external database at IP 10.0.0.5 on port 5432, and denies all other egress. Which policy BEST achieves this?
⚠ Common exam trap
CKS often tests the trap of using 0.0.0.0/0 with a port filter, which looks restrictive but actually allows any destination on that port — candidates must verify the CIDR matches the exact target IP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: db-egress spec: podSelector: {} policyTypes: - Egress egress: - to: - ipBlock: cidr: 10.0.0.5/32 ports: - port: 5432
The correct policy uses an ipBlock with cidr 10.0.0.5/32 and port 5432, which precisely allows egress only to that single external database IP on the PostgreSQL port. Because policyTypes includes Egress and the egress rule is the only one, all other egress traffic is implicitly denied. This matches the requirement exactly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: db-egress spec: podSelector: {} policyTypes: - Egress egress: - to: - ipBlock: cidr: 0.0.0.0/0 ports: - port: 5432
Why it's wrong here
The ipBlock CIDR 0.0.0.0/0 matches every possible IPv4 destination, so this policy would permit egress to any IP address on TCP port 5432, not just the database at 10.0.0.5. Although the port restriction narrows the traffic type, the destination scope is far too broad, violating least-privilege by enabling connections to arbitrary hosts on that port. Because policyTypes includes Egress, all other egress is denied, but this rule still allows far more than intended, making it incorrect.
- ✗
apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: db-egress spec: podSelector: {} policyTypes: - Egress egress: - to: - podSelector: matchLabels: app: db
Why it's wrong here
A podSelector in an egress rule matches destination pods inside the same Kubernetes namespace, not arbitrary external IP addresses. The database at 10.0.0.5 is outside the cluster, so this rule cannot match it and will effectively be a no-op for that traffic. Additionally, this rule omits any port restriction, so even if the database were an in-cluster pod labeled app=db, it would permit all ports, not just 5432.
- ✗
apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: db-egress spec: podSelector: {} policyTypes: - Egress egress: []
Why it's wrong here
With policyTypes set to Egress and an empty egress array, the NetworkPolicy installs a default-deny rule for all outbound traffic from the selected pods, allowing nothing. The desired connection to 10.0.0.5:5432 is therefore blocked, because no egress rule explicitly permits it. An empty egress list is equivalent to having no egress rules at all, so it cannot satisfy an allow requirement.
- ✓
apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: db-egress spec: podSelector: {} policyTypes: - Egress egress: - to: - ipBlock: cidr: 10.0.0.5/32 ports: - port: 5432
Why this is correct
The ipBlock with CIDR 10.0.0.5/32 precisely identifies the database's IP address, and the port 5432 restricts traffic to the database listener, thereby permitting only the intended communication. Because policyTypes includes Egress and this is the sole egress rule, it also establishes an implicit default-deny for any other outbound traffic, aligning with least-privilege security. This is the correct configuration for allowing egress to a specific external IP and port.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.