Practice ICA Securing Workloads questions with full explanations on every answer.
Start practicing
Securing Workloads — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which TWO of the following are valid modes for PeerAuthentication?
2A security team requires that all traffic to the 'payments' service must originate from a specific IP range (10.0.0.0/24). How can this be achieved?
3What is the default behavior of Istio when no AuthorizationPolicy is present for a workload?
4You have a requirement to use a custom JWT claim to authorize users. How can you map this claim in an 'AuthorizationPolicy'?
5Which Istio component is responsible for enforcing the AuthorizationPolicy at the workload level?
6Which THREE actions are required to successfully secure a workload using OIDC and JWT authentication in Istio?
7You have a namespace 'finance' where all traffic must be encrypted using mutual TLS. You apply a PeerAuthentication policy with 'mode: STRICT' at the namespace scope. A developer reports that a legacy service in the same namespace is failing to communicate. What is the most likely reason?
8You want to allow traffic only from a specific namespace 'prod' to the 'backend' service. How should you define the 'AuthorizationPolicy'?
9Which THREE items are included in an Istio SPIFFE ID?
10Which THREE fields in an AuthorizationPolicy are evaluated under the 'rules' section?
11If you apply an AuthorizationPolicy with a 'DENY' action and an 'ALLOW' action in the same namespace, how does Istio resolve them?
12What is the primary function of the 'root-cert.pem' file in the Istio control plane?
13What does the 'jwksUri' field in a RequestAuthentication resource define?
14Which of the following is true regarding PeerAuthentication and sidecar-less ambient mode?
15How do you ensure that a workload ignores a global PeerAuthentication policy?
16Which protocol is used for the Istio data plane mTLS communication?
17What is the primary purpose of the 'RequestAuthentication' resource?
18Which of the following describes the role of the 'trust-domain' in Istio?
19In an AuthorizationPolicy, what does the 'ALLOW' action mean when combined with an empty rule set?
20Which THREE actions occur when 'mode: STRICT' is set in a PeerAuthentication policy?
21Which THREE components are involved in the Istio certificate management process?
22Which tool would you use to verify if a pod has an active mTLS connection?
23Which TWO scenarios indicate that a PeerAuthentication policy is working correctly?
24What happens if a RequestAuthentication policy is applied, but no JWT is provided in the request?
25How can you restrict a service to only accept requests from users authenticated via a specific JWT issuer?
26What does an AuthorizationPolicy's 'operation' field represent?
27You have a global PeerAuthentication policy. What is the effect of applying a new PeerAuthentication policy in the 'default' namespace with no selector?
28Which THREE elements are part of a 'RequestAuthentication' resource?
29What is the correct syntax for a principal in an AuthorizationPolicy?
30If you set 'mode: PERMISSIVE' in PeerAuthentication, what does this allow?
31Why might a 'RequestAuthentication' policy fail to validate a JWT even if the issuer is correct?
32What happens when an AuthorizationPolicy is applied to a workload without a sidecar?
33Which of the following is true about the 'principals' vs 'source.principals' fields?
34How can you debug a failing AuthorizationPolicy rule?
35Which THREE things are required for mTLS to be successful?
36Which resource is used to define the root certificate for a custom CA?
37Which command is used to display the currently active PeerAuthentication policies in the mesh?
38What is the result of applying an AuthorizationPolicy that has no 'action' field?
39When using JWT, what is the 'forwardOriginalToken' flag in the RequestAuthentication resource?
40Which THREE conditions must be met for a PeerAuthentication policy to enforce STRICT mTLS?
41How can you restrict traffic to a service based on the presence of a specific request header?
42What is the default behavior of Istio mTLS if no PeerAuthentication policy is applied?
43You have a namespace 'prod' and you need to ensure that all workloads in this namespace only accept mutual TLS (mTLS) encrypted traffic. What is the most effective way to configure this?
44A service 'orders' requires a specific AuthorizationPolicy that allows GET requests only from the 'frontend' service while denying all other methods. Which configuration is correct?
45Your team needs to allow end-users to authenticate using JWT tokens issued by an external OIDC provider. Which resource should you define to validate these tokens?
46When using JWT authentication, where does the Istio sidecar fetch the public key (JWKS) required for token verification?
47You have a legacy service that cannot handle mTLS. How can you exclude this specific service from the namespace-wide STRICT mTLS policy?
48Which field in the AuthorizationPolicy is used to restrict access based on the verified JWT claims?
49Which of the following is NOT a valid action in an Istio AuthorizationPolicy?
50Which component is responsible for distributing the security policies (like AuthorizationPolicy) to the Envoy sidecars?
51You want to implement a 'Deny-All' strategy for your mesh and explicitly whitelist only necessary traffic. What is the correct order to achieve this?
52When multiple AuthorizationPolicies target the same workload, how are they combined?
53Which TWO of the following are true regarding the RequestAuthentication resource?
54Which TWO of the following are valid sources for an AuthorizationPolicy?
55Which attribute can be used in an AuthorizationPolicy to verify that the request was made via mTLS?
56You have an external service 'legacy-db' outside the mesh. You want to allow access to it from 'webapp' while ensuring 'webapp' presents a valid certificate. How is this achieved?
57Which THREE items are required to successfully authenticate a user via JWT in Istio?
58Which TWO of the following are true regarding PeerAuthentication policies?
59Which THREE factors influence whether a service in the mesh will accept traffic?
The Securing Workloads domain covers the key concepts tested in this area of the ICA exam blueprint published by CNCF / Linux Foundation. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all ICA domains — no account required.
The Courseiva ICA question bank contains 59 questions in the Securing Workloads domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Securing Workloads domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included