Courseiva
Kubernetes Fundamentals →easyMultiple Select

KCNA Kubernetes Fundamentals Practice Question

Which THREE statements about Kubernetes Namespaces are correct?

⚠ Common exam trap

CNCF often tests the misconception that Namespaces provide automatic network isolation, but in reality, network policies must be explicitly defined to restrict traffic between namespaces.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Namespaces provide a way to divide cluster resources between multiple users or teams.

Option A is correct because Kubernetes Namespaces are designed as a logical partitioning mechanism that lets a single physical cluster be shared among multiple users, teams, or projects, scoping names and resource usage per group. Option D is correct because deleting a Namespace triggers cascading deletion of all namespaced objects contained in it (e.g., Pods, Services, ConfigMaps), so the namespace and its contents are removed together. Option E is correct because ResourceQuota objects are applied at the namespace scope to cap aggregate consumption of resources such as CPU, memory, and object counts within that namespace. Option B is incorrect because many resources are cluster-scoped and cannot live in a namespace, such as Nodes, PersistentVolumes, ClusterRoles, and StorageClasses. Option C is incorrect because namespaces do not enforce network isolation by default; without a NetworkPolicy, pods in different namespaces can communicate freely, so isolation must be explicitly configured.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Namespaces provide a way to divide cluster resources between multiple users or teams.

    Why this is correct

    Namespaces create logical partitions within a single cluster, letting teams share underlying nodes while scoping names, RBAC and quotas per partition. This satisfies the stem's requirement for dividing cluster resources between multiple users or teams without provisioning separate clusters.

  • ✗

    All Kubernetes resources must be created within a namespace.

    Why it's wrong here

    Cluster-scoped resources such as Nodes, PersistentVolumes and ClusterRoles exist outside any namespace, so the blanket claim fails. Namespaces suit isolating namespaced workloads, but the statement's universal quantifier is the flaw; it would only hold if every resource type were namespaced, which Kubernetes does not enforce.

  • ✗

    Namespaces provide network isolation by default.

    Why it's wrong here

    Namespaces do not isolate network traffic by default; pods in different namespaces can communicate freely unless a NetworkPolicy restricts them. It is tempting because namespaces group and scope resources logically, but network isolation requires explicit NetworkPolicy objects, not the namespace boundary itself.

  • ✓

    Deleting a namespace will delete all resources in it.

    Why this is correct

    Namespace deletion triggers cascading garbage collection: the API server removes every namespaced object within it, including pods, services, config maps and secrets. This satisfies the stem's statement that deleting a namespace deletes all resources in it, unlike deleting individual objects.

  • ✓

    Resource quotas can be applied to a namespace to limit total resource consumption.

    Why this is correct

    ResourceQuota objects are namespace-scoped, capping aggregate CPU, memory, object counts and storage consumed by all pods in that namespace. This directly satisfies the stem's requirement to limit total resource consumption per namespace, preventing one tenant exhausting shared cluster capacity.

About these practice questions

This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.