CKS Minimize Microservice Vulnerabilities Practice Question
Which THREE of the following are true about Istio PeerAuthentication? (Select THREE.)
⚠ Common exam trap
Candidates often confuse the role of Istio PeerAuthentication (which controls mTLS mode) with DestinationRule (which controls traffic routing and TLS settings for outbound connections). They may incorrectly think a DestinationRule is required for PeerAuthentication to work, when in fact PeerAuthentication is independent and only sets the mTLS policy for inbound traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It can be used to enable mTLS for all workloads in a namespace
Istio PeerAuthentication defines the mutual TLS (mTLS) mode for traffic between services within a mesh. When applied at the namespace level, it enforces the specified mTLS mode (e.g., STRICT) for all workloads in that namespace, ensuring that all inter-service communication uses TLS certificates for identity and encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It can be used to enable mTLS for all workloads in a namespace
Why this is correct
PeerAuthentication is an Istio security policy that defines mTLS enforcement at the mesh, namespace, or workload level. When applied to a namespace, it applies to all workloads in that namespace, enforcing mTLS by setting the TLS mode. This is the straightforward way to require mutual TLS for every service in that namespace without configuring each deployment individually.
- ✗
It configures how traffic is routed between services
Why it's wrong here
Traffic routing between services is governed by Istio's VirtualService and DestinationRule resources, not by PeerAuthentication. Though PeerAuthentication is part of the security.istio.io API group, it only sets server-side TLS requirements for inbound connections to a workload. It never influences which service or version a request is forwarded to, so this statement is incorrect.
- ✓
It can specify TLS mode as STRICT, PERMISSIVE, or DISABLE
Why this is correct
The PeerAuthentication resource exposes an mtls.mode field that accepts exactly three values: STRICT, PERMISSIVE, and DISABLE. STRICT requires all incoming connections to use mutual TLS, PERMISSIVE accepts both plaintext and mTLS to aid migration, and DISABLE turns off mTLS for the selected workloads. This mode is inherited hierarchically, allowing mesh-wide, namespace-wide, and workload-specific settings.
- ✗
It requires a DestinationRule to define the TLS settings
Why it's wrong here
PeerAuthentication operates independently of DestinationRule; it configures server-side (inbound) mTLS enforcement for the workloads it is applied to. DestinationRule, in contrast, defines client-side (outbound) policies like connection pool size or TLS settings used when a client calls a service. You can enable strict mTLS with PeerAuthentication alone; a DestinationRule is only needed when you want to control client-side TLS behavior explicitly.
- ✓
It can be applied to specific workloads using label selectors
Why this is correct
PeerAuthentication has a selector field that uses workload labels to target specific pods, similar to how a Service selects pods. For example, a policy with a selector matching app: payment will enforce mTLS only on those workloads, while an empty selector applies to the entire scope. This allows fine-grained security control within a namespace where different workloads may have different mTLS requirements.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.