Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityEasy

A security architect is designing a multi-tenant Kubernetes cluster where different teams will deploy applications. To enforce strict isolation and prevent tenants from accessing each other's network resources, which Kubernetes object is primarily used to control ingress and egress traffic at the IP address or port level?

  1. AIngress Controller
  2. BService
  3. CNetworkPolicy
  4. DEndpointSlice
Show answer & explanation

Correct answer: C. NetworkPolicy

NetworkPolicy is the Kubernetes resource designed to control network traffic flow between Pods, Namespaces, and external endpoints. It allows defining rules for ingress and egress traffic, enforcing network isolation.

Why the other options are wrong

  • A. An Ingress Controller manages external access to services, typically HTTP/S, not internal Pod-to-Pod isolation.
  • B. A Service defines a logical set of Pods and a policy by which to access them, but does not control network traffic rules.
  • D. An EndpointSlice provides a scalable way to track network endpoints for Services, but does not enforce network policies.

Kubernetes NetworkPolicy

A Kubernetes resource that specifies how groups of Pods are allowed to communicate with each other and with other network endpoints, enabling network isolation and security.

  • Defines rules for ingress (incoming) and egress (outgoing) traffic.
  • Can target Pods based on labels.
  • Requires a NetworkPolicy-aware CNI plugin to enforce.

Memory trick: NetworkPolicy is the traffic cop for your Pods, directing who can go where.

More Cloud Native Security questions