Courseiva
Kubernetes Fundamentals →hardMultiple Choice

KCNA Kubernetes Fundamentals Practice Question

An administrator is configuring a NetworkPolicy to allow ingress traffic to Pods with label `role=db` only from Pods with label `role=api` on TCP port 6379. The NetworkPolicy is applied in the same namespace as the Pods. Which NetworkPolicy YAML correctly implements this requirement?

⚠ Common exam trap

The trap here is using an empty namespaceSelector, which allows all Pods in all namespaces, instead of a podSelector to restrict to specific Pods.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-api-to-db spec: podSelector: matchLabels: role: db policyTypes: - Ingress ingress: - from: - podSelector: matchLabels: role: api ports: - protocol: TCP port: 6379

The correct NetworkPolicy selects the target Pods (role=db) and defines an ingress rule that allows traffic from Pods labeled role=api on TCP port 6379. It uses a podSelector within the from clause to match the source Pods. Since both sets of Pods are in the same namespace, no namespaceSelector is required. The other options either allow too much traffic, reverse the roles, or add unnecessary egress restrictions that could disrupt other traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-api-to-db spec: podSelector: matchLabels: role: db policyTypes: - Ingress ingress: - from: - podSelector: matchLabels: role: api ports: - protocol: TCP port: 6379

    Why this is correct

    This policy selects Pods with role=db and allows ingress from Pods with role=api on TCP port 6379. It correctly uses podSelector in the ingress rule to match the source Pods and specifies the port. Since it is in the same namespace, no namespaceSelector is needed. This precisely implements the requirement, allowing only the intended traffic.

  • ✗

    apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-api-to-db spec: podSelector: matchLabels: role: db policyTypes: - Ingress ingress: - from: - podSelector: matchLabels: role: api ports: - protocol: TCP port: 6379 egress: - to: - podSelector: matchLabels: role: api ports: - protocol: TCP port: 6379

    Why it's wrong here

    This policy includes both ingress and egress rules. While the ingress rule is correct, the egress rule restricts outbound traffic from the db Pods to only the api Pods on port 6379. This is unnecessary and may break other outbound connections from the db Pods. The requirement only specifies ingress restrictions. Adding egress could cause unintended connectivity issues.

  • ✗

    apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-api-to-db spec: podSelector: matchLabels: role: db policyTypes: - Ingress ingress: - from: - namespaceSelector: {} ports: - protocol: TCP port: 6379

    Why it's wrong here

    This policy allows ingress from all Pods in all namespaces because namespaceSelector: {} matches every namespace. It does not restrict to Pods with role=api, so any Pod can connect to the db Pods on port 6379. This violates the requirement to allow only from role=api. The empty namespaceSelector is a common mistake that broadens access unintentionally.

  • ✗

    apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-api-to-db spec: podSelector: matchLabels: role: api policyTypes: - Ingress ingress: - from: - podSelector: matchLabels: role: db ports: - protocol: TCP port: 6379

    Why it's wrong here

    This policy selects Pods with role=api and allows ingress from Pods with role=db. It reverses the roles: it applies to the API Pods and allows traffic from the database Pods. The requirement is to allow traffic to the database Pods from the API Pods. This policy would not achieve the desired effect and could inadvertently allow unwanted traffic to the API Pods.

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.