Courseiva
KCSA
Kubernetes Security FundamentalshardMultiple SelectObjective-mapped

KCSA Kubernetes Security Fundamentals Practice Question

Which TWO statements are true regarding Kubernetes NetworkPolicy default behaviors?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

By default, all pods in a cluster are non-isolated and accept traffic from any source.

By default, pods are non-isolated (all traffic allowed). When a NetworkPolicy selects pods and specifies ingress/egress, those specific directions become deny-by-default.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • NetworkPolicies automatically block all traffic across all namespaces upon cluster installation.

    Why it's wrong here

    Clusters do not enable default-deny network isolation out of the box.

  • By default, all pods in a cluster are non-isolated and accept traffic from any source.

    Why this is correct

    Cluster networking is open by default until policies are applied.

  • When a NetworkPolicy selects a pod and specifies ingress rules, unallowed ingress traffic is blocked.

    Why this is correct

    Selecting pods with an ingress policy turns on ingress isolation for those pods.

  • Egress traffic is blocked by default even if no NetworkPolicy is created.

    Why it's wrong here

    Egress is allowed by default until egress policies are enforced.

  • NetworkPolicies apply to cluster nodes rather than individual pods.

    Why it's wrong here

    NetworkPolicies operate at the pod level using selectors.

About these practice questions

Courseiva writes every KCSA question from scratch — 320 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official CNCF / Linux Foundation exam blueprint

This KCSA practice question is part of Courseiva's free CNCF / Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCSA exam.