Courseiva
Kubernetes Fundamentals →mediumMultiple Select

KCNA Kubernetes Fundamentals Practice Question

Which TWO are valid reasons to use a Namespace in Kubernetes?

⚠ Common exam trap

CNCF often tests the misconception that Namespaces provide performance benefits or reduce API load, when in reality they are purely a logical isolation and naming boundary with no direct impact on network speed or control plane traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To enforce network policies that restrict traffic between Pods in different Namespaces.

Option A is correct because Namespaces provide a boundary for scoping resources, and NetworkPolicy objects are namespaced resources that select Pods within a namespace; policies can allow or deny ingress/egress traffic to Pods in other namespaces, so namespaces are a valid way to organize and enforce network segmentation between teams or environments. Option C is correct because Namespaces provide logical isolation of cluster resources (Pods, Services, ConfigMaps, etc.) and enforce unique names within each namespace, so two teams can each create a Service named 'web' in their own namespace without collision. Option B is not a reason to use Namespaces, since namespaces do not reduce control-plane API calls; if anything, managing more namespaces adds API objects. Option D is not correct because namespaces are an organizational and isolation construct and do not reduce network latency or improve application performance. Option E is not correct because environment variables for containers are supplied via Pod specs, ConfigMaps, or Secrets, not by namespaces themselves.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    To enforce network policies that restrict traffic between Pods in different Namespaces.

    Why this is correct

    NetworkPolicy objects are namespaced resources, so placing Pods in separate Namespaces lets you apply policies that restrict cross-Namespace traffic. This directly satisfies the stem's requirement to enforce network policies restricting traffic between Pods in different Namespaces.

  • ✗

    To reduce the number of API calls to the control plane.

    Why it's wrong here

    Namespaces partition objects and apply quotas or RBAC boundaries; they do not batch or cache API requests. Reducing control-plane calls is achieved through client-side informers, watch caches or aggregated APIs. The option tempts because namespaced queries feel narrower, yet the API server still processes each call individually.

  • ✓

    To isolate resources and prevent naming collisions between different teams.

    Why this is correct

    Namespaces scope object names, so identically named Deployments or Services can coexist across teams without collision, and resource quotas isolate consumption. This satisfies the stem's requirement to isolate resources and prevent naming collisions between different teams sharing one cluster.

  • ✗

    To improve application performance by reducing latency.

    Why it's wrong here

    Namespaces partition cluster objects for naming, access control and resource quotas; they add no network or scheduling mechanism that reduces latency. Namespaces are the right choice for isolating teams, environments or resource budgets within one cluster.

  • ✗

    To store environment variables for containers.

    Why it's wrong here

    Environment variables are supplied to containers via ConfigMaps, Secrets or pod specs, not Namespaces. Namespaces partition cluster resources and scope names, so this option confuses configuration injection with logical isolation. It tempts because Namespaces do hold metadata, but they never carry runtime environment values.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.