KCNA Container Orchestration Practice Question
An administrator needs to ensure that Pods from two different Deployments cannot communicate with each other. Which Kubernetes resource should be used?
⚠ Common exam trap
Many candidates confuse NetworkPolicy with RBAC or PodSecurityPolicy, mistakenly thinking that authorization or security contexts can control network traffic, when in fact only NetworkPolicy (with a compatible CNI) provides layer 3/4 isolation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NetworkPolicy
NetworkPolicy is the correct resource because it acts as a firewall for Kubernetes Pods, controlling ingress and egress traffic at the IP address and port level using layer 3/4 rules. By applying a NetworkPolicy that denies all traffic between the Pods of the two Deployments (e.g., using podSelector and ingress/egress rules with an empty `from` or `to` block), the administrator can enforce network isolation. This is the native Kubernetes mechanism for restricting Pod-to-Pod communication within a cluster.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
NetworkPolicy
Why this is correct
NetworkPolicy selects Pods by label and defines ingress and egress rules, so denying traffic between the two Deployments' label sets isolates them. It operates at layer 3/4 within the cluster, which RBAC or namespaces alone cannot enforce.
- ✗
RBAC Role
Why it's wrong here
RBAC Role grants or denies API operations on Kubernetes resources; it governs who may act on objects, not whether Pod traffic flows. It is tempting because it restricts access, and would be correct when limiting which users or service accounts can create or modify Deployments.
- ✗
PodSecurityPolicy
Why it's wrong here
PodSecurityPolicy controls security contexts such as privileged mode, host networking and volume types at admission; it never filters Pod-to-Pod packets. It is tempting because it hardens workloads, and would be correct when preventing containers from running as root or mounting host paths.
- ✗
ResourceQuota
Why it's wrong here
ResourceQuota caps aggregate CPU, memory and object counts within a namespace; it enforces consumption limits, not network reachability between Pods. It is tempting because it constrains workloads, and would be correct when preventing one team's namespace from exhausting cluster capacity.
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.