CV0-004 Security Practice Question
A cloud engineer manages a Kubernetes cluster on Google Kubernetes Engine (GKE). An application team reports that a compromised container in the 'payments' namespace attempted to read secrets belonging to the 'analytics' namespace, but the request was denied. The engineer wants to enforce a policy that restricts pod-to-pod traffic so that only pods labeled 'app=frontend' can reach pods labeled 'app=api' on TCP port 8080, while denying all other ingress to the api pods. Which mechanism should the engineer implement?
⚠ Common exam trap
The trap here is assuming VPC-level firewall rules or service mesh mTLS alone can restrict traffic between individual pods, when only a Kubernetes NetworkPolicy object can enforce label-based pod ingress.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Kubernetes NetworkPolicy applied in the api namespace selecting pods with label app=api, with an ingress rule allowing only pods labeled app=frontend on TCP 8080.
Kubernetes NetworkPolicy is the correct tool because it provides label-selector-based ingress control at the pod level. Selecting pods labeled app=api and allowing ingress only from app=frontend on TCP 8080 implements the required least-privilege traffic rule. Node-level VPC firewalls, Services, and mTLS alone cannot express or enforce this pod-label restriction, so the NetworkPolicy is the only option that meets the stated requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A Kubernetes Service of type ClusterIP exposing the api pods, combined with a PodDisruptionBudget to limit access.
Why it's wrong here
A ClusterIP Service only provides stable virtual IP load balancing to a set of pods; it does not restrict which pods may connect. A PodDisruptionBudget controls voluntary disruptions during maintenance, not network access. Neither object enforces the label-based ingress restriction the engineer needs, so unauthorized pods could still reach the api service.
- ✗
A GKE firewall rule (VPC firewall) that allows ingress to the node pool on TCP 8080 from the frontend node pool's IP range only.
Why it's wrong here
VPC firewall rules operate at the node/IP level, not the pod level. Allowing TCP 8080 between node pools would permit any pod scheduled on the frontend nodes to reach any pod on the api nodes, regardless of label. This does not satisfy the requirement that only app=frontend pods reach app=api, and it cannot express label-based pod selectors.
- ✗
An Istio sidecar with mTLS STRICT mode enabled in the payments and analytics namespaces.
Why it's wrong here
Enabling STRICT mTLS authenticates and encrypts traffic between sidecars but does not by itself deny traffic from pods without the app=frontend label. Without an AuthorizationPolicy, any mesh pod with a valid certificate can still connect. mTLS addresses identity and encryption, not the specific allow-list of source labels to destination port required here.
- ✓
A Kubernetes NetworkPolicy applied in the api namespace selecting pods with label app=api, with an ingress rule allowing only pods labeled app=frontend on TCP 8080.
Why this is correct
NetworkPolicy is the native Kubernetes object that controls pod-level ingress and egress. Selecting app=api and permitting only app=frontend on TCP 8080 enforces the least-privilege requirement directly. On GKE, NetworkPolicy enforcement requires a policy-capable CNI (Calico or the built-in GKE Dataplane V2), which the cluster already has since the cross-namespace read was denied by a policy.
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.