Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

What is the primary purpose of using a service mesh like Istio for microservices security?

⚠ Common exam trap

The CKS exam often tests the distinction between network-layer controls (NetworkPolicies) and service-mesh-layer controls (mTLS), so the trap here is that candidates confuse Istio's role in network segmentation with its actual purpose of securing service-to-service communication via encrypted and authenticated mTLS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To provide mTLS communication between services for encrypted and authenticated traffic.

The primary purpose of a service mesh like Istio for microservices security is to enforce mutual TLS (mTLS) between services, ensuring that all inter-service communication is both encrypted and authenticated. This is achieved by injecting sidecar proxies (Envoy) that handle TLS termination and certificate management transparently, without requiring changes to application code.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To replace Kubernetes NetworkPolicies for network segmentation.

    Why it's wrong here

    Kubernetes NetworkPolicies define L3/L4 allow/deny rules enforced by the CNI plugin at the node level, using iptables, eBPF, or similar datapath mechanisms. A service mesh operates as L7 sidecar proxies and cannot replace this kind of network segmentation; it only sees traffic that the pods direct through the proxy, so bypass traffic and host-level paths remain uncovered. While a mesh can add L7 policies like HTTP path rules, the underlying NetworkPolicies are still the layer that restricts raw traffic among pods and namespaces.

  • ✗

    To provide a centralized logging solution.

    Why it's wrong here

    A service mesh is not a logging pipeline; it generates telemetry such as access logs, metrics, and trace spans, but it does not aggregate, store, or index logs across the cluster. Centralized logging is typically implemented with a dedicated stack like Elasticsearch/Fluentd/Kibana or Loki, which collects from all applications and infrastructure. The mesh's traffic logs might feed into such a solution as one source, but the primary purpose of the mesh is to manage and secure service-to-service communication, not to provide observability aggregation.

  • ✗

    To automatically scale pods based on CPU usage.

    Why it's wrong here

    Pod autoscaling based on CPU utilization is implemented by the Horizontal Pod Autoscaler, which reads metrics from the resource metrics API and adjusts the replica count in the Deployment or StatefulSet. A service mesh sits between services and handles traffic routing, TLS, and policies; it has no control over the Kubernetes replication controller or its scaling decisions. Even a mesh's traffic-shifting features adjust request weights among existing pod versions, and they do not modify the number of replicas running in the cluster.

  • ✓

    To provide mTLS communication between services for encrypted and authenticated traffic.

    Why this is correct

    The primary purpose of a service mesh is to enable mutual TLS (mTLS) between services transparently, so each sidecar proxy terminates and re-originates TLS connections, presenting workload identities (typically SPIFFE-based) and verifying the peer's certificate. This ensures all service-to-service traffic is both encrypted in transit and mutually authenticated, preventing eavesdropping, man-in-the-middle attacks, and unauthorized service impersonation. The mesh takes over certificate issuance, rotation, and transmission, which means the application code and containers do not need to embed or manage TLS secrets themselves.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.