Courseiva

200-901 Application Deployment and Security Practice Question

A developer is deploying a web application to a Kubernetes cluster. The application must be reachable from the internet on port 443, and the team wants the cluster to automatically provision a TLS certificate. Which Kubernetes resource should the developer create to expose the application with TLS termination and automatic certificate management?

⚠ Common exam trap

The trap here is assuming that a LoadBalancer Service can terminate TLS and manage certificates, when that is the role of an Ingress and a certificate manager.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An Ingress resource with a TLS section that references a Secret, combined with a certificate manager that issues the certificate.

Exposing an application over HTTPS with automatic certificate management requires an Ingress resource with a TLS section and a certificate manager that provisions the referenced secret. The Ingress handles external routing and TLS termination, while the certificate manager issues and renews certificates. The other resources either do not expose the application or do not manage TLS certificates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    An Ingress resource with a TLS section that references a Secret, combined with a certificate manager that issues the certificate.

    Why this is correct

    This is correct because an Ingress resource can terminate TLS by referencing a TLS secret, and a certificate manager such as cert-manager can automatically provision and renew that secret. The Ingress routes external traffic to the Service, and the TLS section enables HTTPS on port 443. This matches the requirement for automatic certificate management.

  • ✗

    A Service of type LoadBalancer with port 443 and a TLS secret referenced in the Service spec.

    Why it's wrong here

    This fails because a Service of type LoadBalancer exposes the application but does not handle TLS termination or automatic certificate provisioning. Service specs do not support referencing TLS secrets for termination. The developer would still need an ingress controller or certificate manager to handle TLS and certificate issuance.

  • ✗

    A NetworkPolicy that allows inbound traffic on port 443 and a ConfigMap that stores the certificate.

    Why it's wrong here

    This is wrong because a NetworkPolicy controls traffic between pods and does not expose an application to the internet or terminate TLS. A ConfigMap is not designed to store TLS certificates securely and is not used by ingress controllers for TLS termination. Neither resource provides automatic certificate provisioning.

  • ✗

    A PodDisruptionBudget that ensures the application pods remain available during certificate rotation.

    Why it's wrong here

    This fails because a PodDisruptionBudget only controls voluntary disruptions to pods and has nothing to do with exposing the application or managing TLS certificates. It does not provide an external endpoint, TLS termination, or certificate issuance. The developer still needs an Ingress and certificate manager for those functions.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.