KCNA Kubernetes Fundamentals Practice Question
Which THREE statements about Kubernetes Namespaces are correct?
⚠ Common exam trap
CNCF often tests the misconception that Namespaces provide automatic network isolation, but in reality, network policies must be explicitly defined to restrict traffic between namespaces.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Namespaces provide a way to divide cluster resources between multiple users or teams.
Option A is correct because Kubernetes Namespaces are designed as a logical partitioning mechanism that lets a single physical cluster be shared among multiple users, teams, or projects, scoping names and resource usage per group. Option D is correct because deleting a Namespace triggers cascading deletion of all namespaced objects contained in it (e.g., Pods, Services, ConfigMaps), so the namespace and its contents are removed together. Option E is correct because ResourceQuota objects are applied at the namespace scope to cap aggregate consumption of resources such as CPU, memory, and object counts within that namespace. Option B is incorrect because many resources are cluster-scoped and cannot live in a namespace, such as Nodes, PersistentVolumes, ClusterRoles, and StorageClasses. Option C is incorrect because namespaces do not enforce network isolation by default; without a NetworkPolicy, pods in different namespaces can communicate freely, so isolation must be explicitly configured.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Namespaces provide a way to divide cluster resources between multiple users or teams.
Why this is correct
Namespaces create logical partitions within a single cluster, letting teams share underlying nodes while scoping names, RBAC and quotas per partition. This satisfies the stem's requirement for dividing cluster resources between multiple users or teams without provisioning separate clusters.
- ✗
All Kubernetes resources must be created within a namespace.
Why it's wrong here
Cluster-scoped resources such as Nodes, PersistentVolumes and ClusterRoles exist outside any namespace, so the blanket claim fails. Namespaces suit isolating namespaced workloads, but the statement's universal quantifier is the flaw; it would only hold if every resource type were namespaced, which Kubernetes does not enforce.
- ✗
Namespaces provide network isolation by default.
Why it's wrong here
Namespaces do not isolate network traffic by default; pods in different namespaces can communicate freely unless a NetworkPolicy restricts them. It is tempting because namespaces group and scope resources logically, but network isolation requires explicit NetworkPolicy objects, not the namespace boundary itself.
- ✓
Deleting a namespace will delete all resources in it.
Why this is correct
Namespace deletion triggers cascading garbage collection: the API server removes every namespaced object within it, including pods, services, config maps and secrets. This satisfies the stem's statement that deleting a namespace deletes all resources in it, unlike deleting individual objects.
- ✓
Resource quotas can be applied to a namespace to limit total resource consumption.
Why this is correct
ResourceQuota objects are namespace-scoped, capping aggregate CPU, memory, object counts and storage consumed by all pods in that namespace. This directly satisfies the stem's requirement to limit total resource consumption per namespace, preventing one tenant exhausting shared cluster capacity.
Go deeper
Related to this question
Learn chapter
Services and Network Connectivity
Key term
ReplicaSet and Replication
A ReplicaSet ensures a specified number of identical pod instances are running at all times in Kubernetes, using replication to maintain availability and stability.
Key term
Namespaces
A Namespace in Kubernetes is a virtual cluster within a physical cluster that allows you to organize and isolate resources, like an apartment building with separate units for different tenants.
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.