Courseiva

CKS NetworkPolicy default-deny Practice Question

You want to isolate a compromised pod by blocking all network traffic to and from it. Which NetworkPolicy would you apply?

⚠ Common exam trap

CKS often tests the misconception that a policy with only ingress rules blocks all traffic, when in fact egress remains open unless explicitly denied, leading candidates to choose incomplete isolation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A policy with podSelector matching the pod, and policyTypes: [Ingress, Egress] with no rules

To isolate a compromised pod by blocking all network traffic, you need a NetworkPolicy that selects the pod and denies both ingress and egress. A policy with podSelector matching the pod and policyTypes: [Ingress, Egress] with no rules will deny all ingress and egress traffic because an empty rule set means no traffic is allowed. This effectively isolates the pod.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A policy with podSelector matching the pod, and only ingress rules denying from all

    Why it's wrong here

    NetworkPolicy rules are allow rules, not deny rules; you cannot express 'deny from all' as an ingress rule. Additionally, specifying only ingress policies leaves the egress policyTypes unset, meaning egress is not blocked, so the compromised pod can still initiate outbound connections. The correct approach is to include both Ingress and Egress in policyTypes with no rules, which creates an implicit deny for both directions.

  • ✓

    A policy with podSelector matching the pod, and policyTypes: [Ingress, Egress] with no rules

    Why this is correct

    This is the correct method: a NetworkPolicy that selects the compromised pod via its podSelector and explicitly lists policyTypes: [Ingress, Egress] with no rules. With this configuration, the pod is isolated because the policy enforces an implicit deny: any traffic that is not explicitly allowed is dropped, and since there are no allow rules, all ingress and egress traffic is blocked. This effectively quarantines the pod without affecting other pods.

  • ✗

    A policy with podSelector matching the pod, and egress rules allowing to 0.0.0.0/0

    Why it's wrong here

    This option fails because adding an egress rule that allows traffic to 0.0.0.0/0 permits the compromised pod to communicate with any destination, which is the opposite of isolation. Furthermore, if policyTypes does not include Egress, the rule itself is invalid, but even if it does include Egress, the rule explicitly allows all outbound traffic. Even if ingress is denied, the pod can still exfiltrate data or perform lateral movement via outbound connections, so the policy is too permissive.

  • ✗

    A policy with podSelector: {} and no rules

    Why it's wrong here

    The empty podSelector {} matches all pods in the namespace, so the network policy would restrict traffic to and from every pod, not just the compromised one, potentially disrupting the entire application. Additionally, with no rules and no policyTypes specified, the policy defaults to Ingress only, so egress traffic remains unrestricted, meaning the compromised pod can still send data outward. The policy should target only the compromised pod and explicitly include both ingress and egress.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.