KCNA Kubernetes Fundamentals Practice Question
Which TWO statements are true about Kubernetes namespaces? (Select 2)
⚠ Common exam trap
A common misconception is that namespaces inherently provide network isolation, but in reality, network policies are required to enforce traffic rules between namespaces.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Resource quotas can be applied to a namespace to limit resource usage
Option C is correct because ResourceQuota objects are applied at the namespace level to cap aggregate resource consumption (e.g., requests.cpu, limits.memory, pods) for all workloads within that namespace. Option D is correct because namespaces are the standard Kubernetes mechanism for logical multi-tenancy, allowing teams to isolate dev, staging, and prod workloads with separate RBAC, quotas, and naming scopes. Option A is wrong because several resources are cluster-scoped rather than namespaced, such as Node, PersistentVolume, ClusterRole, and Namespace itself. Option B is wrong because namespaces do not enforce network isolation by default; that requires NetworkPolicy objects (and a CNI plugin that supports them). Option E is wrong because deleting a namespace cascades to its namespaced resources only, not cluster-scoped resources, which persist independently.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All Kubernetes resources are namespaced
Why it's wrong here
Namespaced resources include pods, services and ConfigMaps, but cluster-scoped resources such as nodes, PersistentVolumes and StorageClasses sit outside any namespace. It is tempting because most everyday workloads are namespaced, but that mechanism is the correct answer when the question concerns those everyday objects, not the cluster-scoped exceptions.
- ✗
Namespaces provide network isolation by default
Why it's wrong here
Namespaces scope names and resource quotas but apply no network isolation by default; pods across namespaces communicate freely unless NetworkPolicies restrict traffic. It is tempting because namespaces appear to partition the cluster logically, but that mechanism is the correct answer when the question concerns resource organisation, not traffic segmentation.
- ✓
Resource quotas can be applied to a namespace to limit resource usage
Why this is correct
ResourceQuota objects are applied per namespace, capping aggregate CPU, memory, object counts and storage consumed by workloads within that namespace. This enforces multi-tenant limits, confirming the statement that quotas can restrict resource usage at namespace scope.
- ✓
Namespaces can be used to separate environments like dev and prod
Why this is correct
Namespaces provide logical partitioning within a single cluster, letting teams isolate dev and prod workloads without separate clusters. This satisfies the environment-separation constraint, though it is not a hard security boundary — network policies and RBAC must reinforce isolation between tenants sharing the cluster.
- ✗
Deleting a namespace automatically deletes all resources in it, including cluster-scoped resources
Why it's wrong here
Deleting a namespace removes only namespaced resources within it; cluster-scoped objects such as nodes, PersistentVolumes and ClusterRoles persist. It is tempting because namespace deletion does cascade to namespaced children, but that mechanism is the correct answer when the question concerns namespaced resources, not cluster-scoped ones.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Pods and Workload Management
Key term
ReplicaSet and Replication
A ReplicaSet ensures a specified number of identical pod instances are running at all times in Kubernetes, using replication to maintain availability and stability.
Key term
Namespaces
A Namespace in Kubernetes is a virtual cluster within a physical cluster that allows you to organize and isolate resources, like an apartment building with separate units for different tenants.
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.