CKS Minimize Microservice Vulnerabilities Practice Question
Which TWO of the following are valid methods to enforce mTLS in an Istio service mesh? (Select 2)
⚠ Common exam trap
Candidates often confuse the legacy global settings (like `global.mtls.enabled` in ConfigMap) with the modern, granular Istio security resources (PeerAuthentication and DestinationRule), leading them to mistakenly select the deprecated option D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a PeerAuthentication resource with mtls.mode: STRICT
A PeerAuthentication resource with `mtls.mode: STRICT` enforces mutual TLS at the service-to-service communication level within the Istio mesh. This setting ensures that all traffic between sidecar proxies uses mTLS, rejecting any plaintext connections, which directly minimizes the risk of unauthorized access or eavesdropping.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a ServiceEntry for internal services
Why it's wrong here
ServiceEntry is designed to register external services into the mesh service registry, enabling traffic management and observability for endpoints that live outside the cluster. It does not configure any encryption or authentication policies; internal services are already registered automatically via Kubernetes services, so adding them as ServiceEntry would be redundant and does not enforce mutual TLS in any way.
- ✗
Create a VirtualService with tls termination
Why it's wrong here
VirtualService defines routing rules for traffic, such as weighted destinations, retries, and fault injection, operating at the L4/L7 traffic management layer. TLS termination is handled by Gateway resources at the edge, not by VirtualService, and VirtualService has no capability to enforce mTLS between sidecar proxies. The tls field in VirtualService is for routing based on SNI, not for terminating or requiring client certificates.
- ✓
Create a PeerAuthentication resource with mtls.mode: STRICT
Why this is correct
PeerAuthentication is a native Istio security policy that defines how sidecar proxies accept inbound traffic. Setting mtls.mode: STRICT enforces that the server side requires mutual TLS, rejecting any plaintext or non-mutual TLS requests. This works at the sidecar proxy level and applies per namespace, workload, or globally through the mesh root, making it the canonical server-side enforcement mechanism.
- ✗
Set global.mtls.enabled: true in IstioConfigMap
Why it's wrong here
While Istio has a MeshConfig, there is no `global.mtls.enabled` field; the legacy configuration for global mutual TLS was removed in favor of explicit security policies. Even if a similar default were set, it would only establish a default for sidecar TLS settings, not actively enforce strict mTLS, and Istio's current best practice is to use PeerAuthentication and DestinationRule instead.
- ✓
Create a DestinationRule with tls.mode: ISTIO_MUTUAL
Why this is correct
DestinationRule is a client-side configuration that defines how traffic from a source sidecar is sent to a destination. Setting tls.mode: ISTIO_MUTUAL instructs the client sidecar to initiate mutual TLS using Istio's built-in certificates, ensuring the outgoing connection uses mTLS. This complements PeerAuthentication, which enforces the server side, and together they provide end-to-end mTLS for the service.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.