Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

You need to configure a NetworkPolicy that allows egress traffic only to an external database at IP 10.0.0.5 on port 5432, and denies all other egress. Which policy BEST achieves this?

⚠ Common exam trap

CKS often tests the trap of using 0.0.0.0/0 with a port filter, which looks restrictive but actually allows any destination on that port — candidates must verify the CIDR matches the exact target IP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: db-egress spec: podSelector: {} policyTypes: - Egress egress: - to: - ipBlock: cidr: 10.0.0.5/32 ports: - port: 5432

The correct policy uses an ipBlock with cidr 10.0.0.5/32 and port 5432, which precisely allows egress only to that single external database IP on the PostgreSQL port. Because policyTypes includes Egress and the egress rule is the only one, all other egress traffic is implicitly denied. This matches the requirement exactly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: db-egress spec: podSelector: {} policyTypes: - Egress egress: - to: - ipBlock: cidr: 0.0.0.0/0 ports: - port: 5432

    Why it's wrong here

    The ipBlock CIDR 0.0.0.0/0 matches every possible IPv4 destination, so this policy would permit egress to any IP address on TCP port 5432, not just the database at 10.0.0.5. Although the port restriction narrows the traffic type, the destination scope is far too broad, violating least-privilege by enabling connections to arbitrary hosts on that port. Because policyTypes includes Egress, all other egress is denied, but this rule still allows far more than intended, making it incorrect.

  • ✗

    apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: db-egress spec: podSelector: {} policyTypes: - Egress egress: - to: - podSelector: matchLabels: app: db

    Why it's wrong here

    A podSelector in an egress rule matches destination pods inside the same Kubernetes namespace, not arbitrary external IP addresses. The database at 10.0.0.5 is outside the cluster, so this rule cannot match it and will effectively be a no-op for that traffic. Additionally, this rule omits any port restriction, so even if the database were an in-cluster pod labeled app=db, it would permit all ports, not just 5432.

  • ✗

    apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: db-egress spec: podSelector: {} policyTypes: - Egress egress: []

    Why it's wrong here

    With policyTypes set to Egress and an empty egress array, the NetworkPolicy installs a default-deny rule for all outbound traffic from the selected pods, allowing nothing. The desired connection to 10.0.0.5:5432 is therefore blocked, because no egress rule explicitly permits it. An empty egress list is equivalent to having no egress rules at all, so it cannot satisfy an allow requirement.

  • ✓

    apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: db-egress spec: podSelector: {} policyTypes: - Egress egress: - to: - ipBlock: cidr: 10.0.0.5/32 ports: - port: 5432

    Why this is correct

    The ipBlock with CIDR 10.0.0.5/32 precisely identifies the database's IP address, and the port 5432 restricts traffic to the database listener, thereby permitting only the intended communication. Because policyTypes includes Egress and this is the sole egress rule, it also establishes an implicit default-deny for any other outbound traffic, aligning with least-privilege security. This is the correct configuration for allowing egress to a specific external IP and port.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.