Courseiva
Kubernetes Fundamentals →mediumMultiple Choice

KCNA Kubernetes Fundamentals Practice Question

You have a Kubernetes cluster with multiple namespaces. You need to allow communication only from pods with label 'app: frontend' to pods with label 'app: backend' in the same namespace. Which resource should you use?

⚠ Common exam trap

A common mix-up: candidates confuse RBAC (which controls API access) with network access control, assuming that a Role or RoleBinding can restrict pod-to-pod traffic, but RBAC has no effect on network-level communication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NetworkPolicy

NetworkPolicy is a Kubernetes resource that controls ingress and egress traffic between pods based on labels, namespaces, or IP blocks. By defining a NetworkPolicy with a podSelector matching 'app: backend' and an ingress rule that allows traffic only from pods with label 'app: frontend', you can restrict communication to only those pods in the same namespace. This is the correct approach because NetworkPolicy operates at Layer 3/4 (and optionally Layer 7 with Cilium) to enforce network segmentation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    RBAC Role

    Why it's wrong here

    RBAC Role grants API-level permissions on Kubernetes resources; it cannot filter pod-to-pod network traffic by label. NetworkPolicy is the resource that selects pods via label selectors and permits ingress only from 'app: frontend'. RBAC is tempting because it also uses labels and namespaces, but it governs authorisation, not packet flow.

  • ✓

    NetworkPolicy

    Why this is correct

    NetworkPolicy is a namespaced resource applying label selectors to pods, with ingress rules permitting traffic only from pods labelled app: frontend to those labelled app: backend. It enforces the required pod-level segmentation, which plain Services cannot restrict.

  • ✗

    PodSecurityPolicy

    Why it's wrong here

    PodSecurityPolicy governs pod security contexts such as privileged mode and volume types; it does not control which pods may reach which other pods. It is tempting because it is a policy resource applied to pods, and PodSecurityPolicy is correct when you must restrict pod privilege and capability settings.

  • ✗

    Service

    Why it's wrong here

    A Service provides stable virtual IP load balancing to a set of pods; it neither selects traffic by source label nor enforces allow rules. It is tempting because Services connect frontend and backend tiers, and a Service is correct when you need to expose backend pods behind a stable address.

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.