In Kubernetes, how do Network Policies behave when multiple policies are applied to the same set of pods?

Enhance your knowledge for the Kubernetes Certified Network Administrator Test. Utilize flashcards and multiple choice questions with detailed explanations. Prepare effectively for your KCNA exam!

Multiple Choice

In Kubernetes, how do Network Policies behave when multiple policies are applied to the same set of pods?

Explanation:
The traffic control with Network Policies is cumulative. When multiple policies select the same pods, every applicable policy contributes its allowed paths, and the pod’s actual allowed traffic is the intersection of those allowances. In practice, that means adding more policies tends to shrink the set of doors open to traffic rather than expand them. For example, if one policy permits ingress from a certain namespace and another policy permits ingress from another namespace, traffic must satisfy both policies to be allowed, which often results in stricter or even no allowed sources. Since policies restrict both ingress and egress when they apply, they are not about overriding each other or being ignored; they stack to restrict further. That’s why the correct view is that they are additive, with each additional policy further restricting allowed traffic.

The traffic control with Network Policies is cumulative. When multiple policies select the same pods, every applicable policy contributes its allowed paths, and the pod’s actual allowed traffic is the intersection of those allowances. In practice, that means adding more policies tends to shrink the set of doors open to traffic rather than expand them. For example, if one policy permits ingress from a certain namespace and another policy permits ingress from another namespace, traffic must satisfy both policies to be allowed, which often results in stricter or even no allowed sources. Since policies restrict both ingress and egress when they apply, they are not about overriding each other or being ignored; they stack to restrict further. That’s why the correct view is that they are additive, with each additional policy further restricting allowed traffic.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy