KCNA Kubernetes Fundamentals Practice Question
A platform engineer is designing a multi-tenant cluster and must ensure that Pods in different namespaces cannot communicate with each other by default, while allowing specific traffic within each namespace. Which two Kubernetes features are required to achieve this? (Choose two.)
⚠ Common exam trap
The trap here is assuming that creating a NetworkPolicy is sufficient, when in fact the cluster's CNI plugin must also support and enforce NetworkPolicy for the rules to take effect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A CNI plugin that supports NetworkPolicy enforcement
To achieve default-deny between namespaces, you need a NetworkPolicy that denies all ingress in each namespace and a CNI plugin that enforces NetworkPolicy. Without the policy, traffic is allowed by default; without a supporting CNI, the policy has no effect. Together they provide the required isolation and allow specific traffic via additional allow policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Service mesh with mTLS enabled
Why it's wrong here
A service mesh with mTLS encrypts and authenticates traffic but does not by itself block communication between namespaces. Unless authorization policies are configured, Pods can still reach each other. While a service mesh can complement network policies, it is not required to achieve basic default-deny isolation and adds significant complexity.
- ✗
ResourceQuota per namespace
Why it's wrong here
ResourceQuota limits aggregate resource consumption such as CPU, memory, and object counts within a namespace. It does not affect network connectivity between Pods. While useful for multi-tenancy to prevent resource exhaustion, it does not provide network isolation. This is a common misconception when designing multi-tenant clusters.
- ✓
A CNI plugin that supports NetworkPolicy enforcement
Why this is correct
NetworkPolicy resources are only enforced if the cluster's CNI plugin implements them. Plugins like Calico, Cilium, and Weave Net enforce policies, while some basic plugins like Flannel do not. Without a supporting CNI, NetworkPolicy objects are created but have no effect, leaving Pods unrestricted.
- ✗
PodSecurityPolicy restricted to the namespace
Why it's wrong here
PodSecurityPolicy (deprecated and removed in Kubernetes 1.25) controls security contexts such as privileged mode and volume types, not network traffic. It cannot prevent cross-namespace communication. Even its successor, Pod Security Admission, does not enforce network isolation. This feature is unrelated to the requirement.
- ✓
NetworkPolicy with a default deny-all ingress rule in each namespace
Why this is correct
A NetworkPolicy with an empty podSelector and no ingress rules denies all incoming traffic to Pods in that namespace. This enforces isolation between namespaces by default. It must be applied in each namespace because NetworkPolicies are namespace-scoped and additive, so a deny-all policy in one namespace does not affect others.
Go deeper
Related to this question
Learn chapter
Cluster Architecture and Lifecycle Management
Key term
Namespaces
A Namespace in Kubernetes is a virtual cluster within a physical cluster that allows you to organize and isolate resources, like an apartment building with separate units for different tenants.
Key term
ReplicaSet and Replication
A ReplicaSet ensures a specified number of identical pod instances are running at all times in Kubernetes, using replication to maintain availability and stability.
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.