Courseiva
Kubernetes Fundamentals →hardMultiple Select

KCNA Kubernetes Fundamentals Practice Question

A platform engineer is designing a multi-tenant cluster and must ensure that Pods in different namespaces cannot communicate with each other by default, while allowing specific traffic within each namespace. Which two Kubernetes features are required to achieve this? (Choose two.)

⚠ Common exam trap

The trap here is assuming that creating a NetworkPolicy is sufficient, when in fact the cluster's CNI plugin must also support and enforce NetworkPolicy for the rules to take effect.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A CNI plugin that supports NetworkPolicy enforcement

To achieve default-deny between namespaces, you need a NetworkPolicy that denies all ingress in each namespace and a CNI plugin that enforces NetworkPolicy. Without the policy, traffic is allowed by default; without a supporting CNI, the policy has no effect. Together they provide the required isolation and allow specific traffic via additional allow policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Service mesh with mTLS enabled

    Why it's wrong here

    A service mesh with mTLS encrypts and authenticates traffic but does not by itself block communication between namespaces. Unless authorization policies are configured, Pods can still reach each other. While a service mesh can complement network policies, it is not required to achieve basic default-deny isolation and adds significant complexity.

  • ✗

    ResourceQuota per namespace

    Why it's wrong here

    ResourceQuota limits aggregate resource consumption such as CPU, memory, and object counts within a namespace. It does not affect network connectivity between Pods. While useful for multi-tenancy to prevent resource exhaustion, it does not provide network isolation. This is a common misconception when designing multi-tenant clusters.

  • ✓

    A CNI plugin that supports NetworkPolicy enforcement

    Why this is correct

    NetworkPolicy resources are only enforced if the cluster's CNI plugin implements them. Plugins like Calico, Cilium, and Weave Net enforce policies, while some basic plugins like Flannel do not. Without a supporting CNI, NetworkPolicy objects are created but have no effect, leaving Pods unrestricted.

  • ✗

    PodSecurityPolicy restricted to the namespace

    Why it's wrong here

    PodSecurityPolicy (deprecated and removed in Kubernetes 1.25) controls security contexts such as privileged mode and volume types, not network traffic. It cannot prevent cross-namespace communication. Even its successor, Pod Security Admission, does not enforce network isolation. This feature is unrelated to the requirement.

  • ✓

    NetworkPolicy with a default deny-all ingress rule in each namespace

    Why this is correct

    A NetworkPolicy with an empty podSelector and no ingress rules denies all incoming traffic to Pods in that namespace. This enforces isolation between namespaces by default. It must be applied in each namespace because NetworkPolicies are namespace-scoped and additive, so a deny-all policy in one namespace does not affect others.

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.