Courseiva
Kubernetes Fundamentals →hardMultiple Select

KCNA Kubernetes Fundamentals Practice Question

Which THREE of the following are true about Kubernetes Namespaces?

⚠ Common exam trap

The exam often tests the distinction between cluster-scoped and namespaced resources, and the trap here is that candidates mistakenly think all Kubernetes resources are namespaced, when in fact Nodes, PersistentVolumes, and ClusterRoles are cluster-scoped.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NetworkPolicy can be used to control traffic between pods in different namespaces

Option B is correct because NetworkPolicy objects are namespaced and their podSelector rules can reference other namespaces via namespaceSelector, allowing administrators to permit or deny ingress/egress traffic between pods in different namespaces. Option D is correct because ResourceQuota is a namespaced object that caps aggregate resource consumption (e.g., requests.cpu, limits.memory, count/pods) within a single namespace. Option E is correct because namespaces provide logical isolation for namespaced resources such as Pods, Services, Deployments, and ConfigMaps, enabling separate environments or teams to coexist in one cluster. Option A is incorrect because PersistentVolumes are cluster-scoped resources, not namespaced (only PersistentVolumeClaims are namespaced). Option C is incorrect because Nodes are cluster-scoped resources, not namespaced.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PersistentVolumes are namespaced

    Why it's wrong here

    PersistentVolumes are cluster-scoped; only PersistentVolumeClaims are namespaced. It is tempting because claims bind within a namespace and pods reference them there, but the underlying volume object itself is shared cluster-wide and is not isolated by namespace.

  • ✓

    NetworkPolicy can be used to control traffic between pods in different namespaces

    Why this is correct

    NetworkPolicy objects are namespaced and select pods by label, so rules can explicitly permit or deny ingress and egress traffic crossing namespace boundaries. This makes cross-namespace pod traffic controllable rather than implicitly open, satisfying the statement about inter-namespace communication.

  • ✗

    Nodes are namespaced resources

    Why it's wrong here

    Nodes are cluster-scoped, not namespaced; they exist once across the whole cluster and appear in no namespace. It is tempting because pods, services and deployments are namespaced, but node objects, PersistentVolumes and StorageClasses sit outside namespace boundaries.

  • ✓

    You can apply ResourceQuota to limit resource consumption in a namespace

    Why this is correct

    ResourceQuota is a namespaced object that caps aggregate CPU, memory, storage and object counts for all pods within that namespace. It enforces consumption limits at namespace scope, directly satisfying the statement that quotas restrict resource usage per namespace.

  • ✓

    Namespaces are used to isolate resources like Pods and Services

    Why this is correct

    Namespaces partition cluster objects, giving Pods, Services, ConfigMaps and similar resources a scoped name and lifecycle boundary. This logical separation is what the statement describes, though it is not a hard security boundary without NetworkPolicy and RBAC.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

4 more ways this is tested on KCNA

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which THREE statements about Kubernetes Namespaces are correct?

easy
  • ✓ A.Namespaces provide a way to divide cluster resources between multiple users or teams.
  • B.All Kubernetes resources must be created within a namespace.
  • C.Namespaces provide network isolation by default.
  • ✓ D.Deleting a namespace will delete all resources in it.
  • ✓ E.Resource quotas can be applied to a namespace to limit total resource consumption.

Why A: Option A is correct because Kubernetes Namespaces are designed as a logical partitioning mechanism that lets a single physical cluster be shared among multiple users, teams, or projects, scoping names and resource usage per group. Option D is correct because deleting a Namespace triggers cascading deletion of all namespaced objects contained in it (e.g., Pods, Services, ConfigMaps), so the namespace and its contents are removed together. Option E is correct because ResourceQuota objects are applied at the namespace scope to cap aggregate consumption of resources such as CPU, memory, and object counts within that namespace. Option B is incorrect because many resources are cluster-scoped and cannot live in a namespace, such as Nodes, PersistentVolumes, ClusterRoles, and StorageClasses. Option C is incorrect because namespaces do not enforce network isolation by default; without a NetworkPolicy, pods in different namespaces can communicate freely, so isolation must be explicitly configured.

Variation 2. Which TWO statements about Namespaces are correct?

medium
  • ✓ A.Namespaces provide a way to divide cluster resources among multiple users
  • B.Namespaces act as a strong security boundary by default
  • ✓ C.Namespaces help organize objects in a cluster
  • D.Every resource must be created in a namespace
  • E.Resources in different namespaces cannot communicate with each other

Why A: Option A is correct because Kubernetes Namespaces are explicitly designed to divide cluster resources among multiple users or teams, commonly via ResourceQuota and LimitRange objects scoped to a namespace, enabling multi-tenancy and resource partitioning. Option C is correct because Namespaces provide a logical grouping mechanism to organize cluster objects (e.g., pods, services, deployments) into distinct virtual clusters, making management and naming easier. Option B is incorrect because Namespaces are not a strong security boundary by default; they provide no network isolation or RBAC isolation unless NetworkPolicies and RBAC are explicitly configured, and cluster-scoped resources remain shared. Option D is incorrect because not every resource is namespaced — cluster-scoped resources such as Nodes, PersistentVolumes, StorageClasses, and ClusterRoles exist outside any namespace. Option E is incorrect because resources in different namespaces can communicate freely over the network by default (e.g., via ClusterIP services using the fully qualified domain name service.namespace.svc.cluster.local) unless NetworkPolicies restrict traffic.

Variation 3. Which TWO statements about Namespaces are correct?

hard
  • ✓ A.Resource names must be unique within a namespace
  • B.Namespaces provide network isolation by default
  • C.All Kubernetes resources are namespaced
  • ✓ D.Namespaces provide a way to divide cluster resources between multiple users
  • E.You can delete a namespace without affecting the resources inside it

Why A: Option A is correct because within a single namespace, resource names (for a given resource type) must be unique — for example, you cannot have two Pods both named 'web' in the same namespace, though the same name can exist in different namespaces. Option D is correct because namespaces are intended to divide cluster resources among multiple users or teams, commonly combined with ResourceQuota and RBAC to scope access and limit consumption per namespace. Option B is not correct because namespaces do not provide network isolation by default; Pods across namespaces can communicate freely unless NetworkPolicies are applied. Option C is not correct because not all resources are namespaced — cluster-scoped resources such as Nodes, PersistentVolumes, and ClusterRoles exist outside any namespace. Option E is not correct because deleting a namespace deletes all resources contained within it, so it does affect the resources inside.

Variation 4. Which TWO of the following statements about Kubernetes namespaces are true?

hard
  • A.Services in different namespaces cannot communicate with each other
  • B.Every Kubernetes object must be created in a namespace
  • ✓ C.Deleting a namespace will delete all objects in it
  • ✓ D.Namespaces can be used to implement resource quotas
  • E.Namespaces provide a way to divide cluster resources between multiple users

Why C: Option C is correct because deleting a namespace triggers cascading deletion of all resources contained within it, so every object scoped to that namespace is removed along with it. Option D is correct because ResourceQuota objects are applied at the namespace level, allowing administrators to cap aggregate CPU, memory, and object counts per namespace. Option A is false because Services in different namespaces can communicate via fully qualified DNS names such as service.namespace.svc.cluster.local. Option B is false because cluster-scoped objects like Nodes, PersistentVolumes, and ClusterRoles are not created in a namespace. Option E is misleading because namespaces alone do not divide resources; resource division is enforced through quotas and limit ranges, not by the namespace object itself.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.