Courseiva
Kubernetes Fundamentals →hardMultiple Select

KCNA Kubernetes Fundamentals Practice Question

Which TWO statements about Namespaces are correct?

⚠ Common exam trap

The KCNA exam often tests the misconception that namespaces provide automatic network isolation, when in fact they only provide logical grouping and resource quota boundaries, not network segmentation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Resource names must be unique within a namespace

Option A is correct because within a single namespace, resource names (for a given resource type) must be unique — for example, you cannot have two Pods both named 'web' in the same namespace, though the same name can exist in different namespaces. Option D is correct because namespaces are intended to divide cluster resources among multiple users or teams, commonly combined with ResourceQuota and RBAC to scope access and limit consumption per namespace. Option B is not correct because namespaces do not provide network isolation by default; Pods across namespaces can communicate freely unless NetworkPolicies are applied. Option C is not correct because not all resources are namespaced — cluster-scoped resources such as Nodes, PersistentVolumes, and ClusterRoles exist outside any namespace. Option E is not correct because deleting a namespace deletes all resources contained within it, so it does affect the resources inside.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Resource names must be unique within a namespace

    Why this is correct

    Within a single namespace, object names must be unique for a given resource type, because the API server scopes identity by namespace plus name. This satisfies the stem's requirement for a correct Namespaces statement, unlike cross-namespace naming, which may legitimately repeat.

  • ✗

    Namespaces provide network isolation by default

    Why it's wrong here

    Namespaces scope object names and RBAC, but pod-to-pod traffic flows freely across them; isolation requires NetworkPolicy objects. It tempts because namespaces look like security boundaries, and they are the correct choice when you need to divide a cluster for multi-tenancy, quotas or name collision avoidance.

  • ✗

    All Kubernetes resources are namespaced

    Why it's wrong here

    Cluster-scoped resources such as Nodes, PersistentVolumes, StorageClasses and ClusterRoles exist outside any namespace. It tempts because most everyday workload objects are namespaced, so the rule appears universal; namespacing is the right model when you need to partition ordinary application resources per team or environment.

  • ✓

    Namespaces provide a way to divide cluster resources between multiple users

    Why this is correct

    Namespaces partition a single cluster into virtual scopes, letting administrators apply quotas, RBAC and resource limits per namespace. This divides cluster resources between multiple users or teams, directly satisfying the stem's requirement for a correct statement about Namespaces.

  • ✗

    You can delete a namespace without affecting the resources inside it

    Why it's wrong here

    Deleting a namespace triggers cascading deletion of every resource within it, so those resources are destroyed, not preserved. It tempts because namespaces do act as logical grouping boundaries, which is exactly why you would delete one deliberately to tear down an entire environment in a single operation.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.