Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

Which THREE of the following are true about Istio PeerAuthentication? (Select THREE.)

⚠ Common exam trap

Candidates often confuse the role of Istio PeerAuthentication (which controls mTLS mode) with DestinationRule (which controls traffic routing and TLS settings for outbound connections). They may incorrectly think a DestinationRule is required for PeerAuthentication to work, when in fact PeerAuthentication is independent and only sets the mTLS policy for inbound traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It can be used to enable mTLS for all workloads in a namespace

Istio PeerAuthentication defines the mutual TLS (mTLS) mode for traffic between services within a mesh. When applied at the namespace level, it enforces the specified mTLS mode (e.g., STRICT) for all workloads in that namespace, ensuring that all inter-service communication uses TLS certificates for identity and encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    It can be used to enable mTLS for all workloads in a namespace

    Why this is correct

    PeerAuthentication is an Istio security policy that defines mTLS enforcement at the mesh, namespace, or workload level. When applied to a namespace, it applies to all workloads in that namespace, enforcing mTLS by setting the TLS mode. This is the straightforward way to require mutual TLS for every service in that namespace without configuring each deployment individually.

  • ✗

    It configures how traffic is routed between services

    Why it's wrong here

    Traffic routing between services is governed by Istio's VirtualService and DestinationRule resources, not by PeerAuthentication. Though PeerAuthentication is part of the security.istio.io API group, it only sets server-side TLS requirements for inbound connections to a workload. It never influences which service or version a request is forwarded to, so this statement is incorrect.

  • ✓

    It can specify TLS mode as STRICT, PERMISSIVE, or DISABLE

    Why this is correct

    The PeerAuthentication resource exposes an mtls.mode field that accepts exactly three values: STRICT, PERMISSIVE, and DISABLE. STRICT requires all incoming connections to use mutual TLS, PERMISSIVE accepts both plaintext and mTLS to aid migration, and DISABLE turns off mTLS for the selected workloads. This mode is inherited hierarchically, allowing mesh-wide, namespace-wide, and workload-specific settings.

  • ✗

    It requires a DestinationRule to define the TLS settings

    Why it's wrong here

    PeerAuthentication operates independently of DestinationRule; it configures server-side (inbound) mTLS enforcement for the workloads it is applied to. DestinationRule, in contrast, defines client-side (outbound) policies like connection pool size or TLS settings used when a client calls a service. You can enable strict mTLS with PeerAuthentication alone; a DestinationRule is only needed when you want to control client-side TLS behavior explicitly.

  • ✓

    It can be applied to specific workloads using label selectors

    Why this is correct

    PeerAuthentication has a selector field that uses workload labels to target specific pods, similar to how a Service selects pods. For example, a policy with a selector matching app: payment will enforce mTLS only on those workloads, while an empty selector applies to the entire scope. This allows fine-grained security control within a namespace where different workloads may have different mTLS requirements.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.