Courseiva
Kubernetes Fundamentals →hardMultiple Select

KCNA Kubernetes Fundamentals Practice Question

Which TWO statements are true about Kubernetes namespaces? (Select 2)

⚠ Common exam trap

A common misconception is that namespaces inherently provide network isolation, but in reality, network policies are required to enforce traffic rules between namespaces.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Resource quotas can be applied to a namespace to limit resource usage

Option C is correct because ResourceQuota objects are applied at the namespace level to cap aggregate resource consumption (e.g., requests.cpu, limits.memory, pods) for all workloads within that namespace. Option D is correct because namespaces are the standard Kubernetes mechanism for logical multi-tenancy, allowing teams to isolate dev, staging, and prod workloads with separate RBAC, quotas, and naming scopes. Option A is wrong because several resources are cluster-scoped rather than namespaced, such as Node, PersistentVolume, ClusterRole, and Namespace itself. Option B is wrong because namespaces do not enforce network isolation by default; that requires NetworkPolicy objects (and a CNI plugin that supports them). Option E is wrong because deleting a namespace cascades to its namespaced resources only, not cluster-scoped resources, which persist independently.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    All Kubernetes resources are namespaced

    Why it's wrong here

    Namespaced resources include pods, services and ConfigMaps, but cluster-scoped resources such as nodes, PersistentVolumes and StorageClasses sit outside any namespace. It is tempting because most everyday workloads are namespaced, but that mechanism is the correct answer when the question concerns those everyday objects, not the cluster-scoped exceptions.

  • ✗

    Namespaces provide network isolation by default

    Why it's wrong here

    Namespaces scope names and resource quotas but apply no network isolation by default; pods across namespaces communicate freely unless NetworkPolicies restrict traffic. It is tempting because namespaces appear to partition the cluster logically, but that mechanism is the correct answer when the question concerns resource organisation, not traffic segmentation.

  • ✓

    Resource quotas can be applied to a namespace to limit resource usage

    Why this is correct

    ResourceQuota objects are applied per namespace, capping aggregate CPU, memory, object counts and storage consumed by workloads within that namespace. This enforces multi-tenant limits, confirming the statement that quotas can restrict resource usage at namespace scope.

  • ✓

    Namespaces can be used to separate environments like dev and prod

    Why this is correct

    Namespaces provide logical partitioning within a single cluster, letting teams isolate dev and prod workloads without separate clusters. This satisfies the environment-separation constraint, though it is not a hard security boundary — network policies and RBAC must reinforce isolation between tenants sharing the cluster.

  • ✗

    Deleting a namespace automatically deletes all resources in it, including cluster-scoped resources

    Why it's wrong here

    Deleting a namespace removes only namespaced resources within it; cluster-scoped objects such as nodes, PersistentVolumes and ClusterRoles persist. It is tempting because namespace deletion does cascade to namespaced children, but that mechanism is the correct answer when the question concerns namespaced resources, not cluster-scoped ones.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.