CKS Minimize Microservice Vulnerabilities Practice Question
In the context of service mesh (e.g., Istio), which resource is used to enforce mutual TLS (mTLS) between services in a specific namespace?
⚠ Common exam trap
The CKS exam often tests the distinction between PeerAuthentication (for mTLS enforcement on incoming traffic) and DestinationRule (for TLS settings on outgoing traffic), causing candidates to confuse the two resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PeerAuthentication
PeerAuthentication is the correct resource because it defines the mutual TLS (mTLS) mode for workloads within a namespace or mesh. In Istio, PeerAuthentication allows you to enforce STRICT mTLS, which requires all traffic between services in the specified namespace to use TLS certificates for both client and server authentication, preventing plaintext or unauthenticated communication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
PeerAuthentication
Why this is correct
The PeerAuthentication custom resource defines the mTLS mode that workloads must adopt when receiving connections from other services in the mesh. It supports modes like STRICT, PERMISSIVE, and DISABLE, and is enforced by the sidecar Envoy proxies on the server side. This is the security policy resource that directly governs mTLS settings, making it the correct answer.
- ✗
VirtualService
Why it's wrong here
A VirtualService is used exclusively for traffic routing, allowing you to match request attributes like URI or headers and send traffic to specific destination subsets. It does not define any mTLS or authentication policies; a VirtualService works alongside a DestinationRule for routing, but the actual mTLS enforcement is outside its scope. Since the question asks about mTLS settings for workloads, VirtualService cannot be the answer.
- ✗
DestinationRule
Why it's wrong here
DestinationRule configures client-side traffic policies — such as load balancing algorithms, connection pool limits, and outlier detection — for traffic sent to a destination. It can carry a trafficPolicy.tls block with settings like ISTIO_MUTUAL, but that configures how the client initiates TLS, not the server-side mTLS enforcement policy for the workload as a whole. That server-side mTLS policy is the responsibility of PeerAuthentication, which is why DestinationRule is incorrect here.
- ✗
ServiceEntry
Why it's wrong here
A ServiceEntry is used to add external services to the mesh's service registry so that the sidecar proxies can route to and apply policies to those endpoints. While a ServiceEntry can specify TLS parameters for connecting to an external service, it does not define mTLS settings for workloads that are already inside the mesh. It addresses ingress/egress discovery, not the mutual TLS posture of mesh workloads, so it is not the correct resource.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.