KCNA Kubernetes Fundamentals Practice Question
An administrator is configuring a NetworkPolicy to allow ingress traffic to Pods with label `role=db` only from Pods with label `role=api` on TCP port 6379. The NetworkPolicy is applied in the same namespace as the Pods. Which NetworkPolicy YAML correctly implements this requirement?
⚠ Common exam trap
The trap here is using an empty namespaceSelector, which allows all Pods in all namespaces, instead of a podSelector to restrict to specific Pods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-api-to-db spec: podSelector: matchLabels: role: db policyTypes: - Ingress ingress: - from: - podSelector: matchLabels: role: api ports: - protocol: TCP port: 6379
The correct NetworkPolicy selects the target Pods (role=db) and defines an ingress rule that allows traffic from Pods labeled role=api on TCP port 6379. It uses a podSelector within the from clause to match the source Pods. Since both sets of Pods are in the same namespace, no namespaceSelector is required. The other options either allow too much traffic, reverse the roles, or add unnecessary egress restrictions that could disrupt other traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-api-to-db spec: podSelector: matchLabels: role: db policyTypes: - Ingress ingress: - from: - podSelector: matchLabels: role: api ports: - protocol: TCP port: 6379
Why this is correct
This policy selects Pods with role=db and allows ingress from Pods with role=api on TCP port 6379. It correctly uses podSelector in the ingress rule to match the source Pods and specifies the port. Since it is in the same namespace, no namespaceSelector is needed. This precisely implements the requirement, allowing only the intended traffic.
- ✗
apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-api-to-db spec: podSelector: matchLabels: role: db policyTypes: - Ingress ingress: - from: - podSelector: matchLabels: role: api ports: - protocol: TCP port: 6379 egress: - to: - podSelector: matchLabels: role: api ports: - protocol: TCP port: 6379
Why it's wrong here
This policy includes both ingress and egress rules. While the ingress rule is correct, the egress rule restricts outbound traffic from the db Pods to only the api Pods on port 6379. This is unnecessary and may break other outbound connections from the db Pods. The requirement only specifies ingress restrictions. Adding egress could cause unintended connectivity issues.
- ✗
apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-api-to-db spec: podSelector: matchLabels: role: db policyTypes: - Ingress ingress: - from: - namespaceSelector: {} ports: - protocol: TCP port: 6379
Why it's wrong here
This policy allows ingress from all Pods in all namespaces because namespaceSelector: {} matches every namespace. It does not restrict to Pods with role=api, so any Pod can connect to the db Pods on port 6379. This violates the requirement to allow only from role=api. The empty namespaceSelector is a common mistake that broadens access unintentionally.
- ✗
apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-api-to-db spec: podSelector: matchLabels: role: api policyTypes: - Ingress ingress: - from: - podSelector: matchLabels: role: db ports: - protocol: TCP port: 6379
Why it's wrong here
This policy selects Pods with role=api and allows ingress from Pods with role=db. It reverses the roles: it applies to the API Pods and allows traffic from the database Pods. The requirement is to allow traffic to the database Pods from the API Pods. This policy would not achieve the desired effect and could inadvertently allow unwanted traffic to the API Pods.
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.