問題文
A platform team creates a new namespace for a product team and applies no NetworkPolicy objects to it. A reviewer asks what the traffic behavior is for the pods in that namespace at that moment. What is the correct answer?
選択肢
- All ingress traffic is denied and all egress traffic is allowed, because the cluster applies a default deny rule for incoming connections until the namespace declares which sources it accepts.
- The behavior depends on the Pod Security Standards profile of the namespace.
- All ingress and egress traffic to and from those pods is allowed, because a pod is non-isolated until a policy selects it.
- All traffic is denied until the platform team applies a policy that allows it.