Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

Which TWO of the following are valid methods to enforce mTLS in an Istio service mesh? (Select 2)

⚠ Common exam trap

Candidates often confuse the legacy global settings (like `global.mtls.enabled` in ConfigMap) with the modern, granular Istio security resources (PeerAuthentication and DestinationRule), leading them to mistakenly select the deprecated option D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a PeerAuthentication resource with mtls.mode: STRICT

A PeerAuthentication resource with `mtls.mode: STRICT` enforces mutual TLS at the service-to-service communication level within the Istio mesh. This setting ensures that all traffic between sidecar proxies uses mTLS, rejecting any plaintext connections, which directly minimizes the risk of unauthorized access or eavesdropping.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a ServiceEntry for internal services

    Why it's wrong here

    ServiceEntry is designed to register external services into the mesh service registry, enabling traffic management and observability for endpoints that live outside the cluster. It does not configure any encryption or authentication policies; internal services are already registered automatically via Kubernetes services, so adding them as ServiceEntry would be redundant and does not enforce mutual TLS in any way.

  • ✗

    Create a VirtualService with tls termination

    Why it's wrong here

    VirtualService defines routing rules for traffic, such as weighted destinations, retries, and fault injection, operating at the L4/L7 traffic management layer. TLS termination is handled by Gateway resources at the edge, not by VirtualService, and VirtualService has no capability to enforce mTLS between sidecar proxies. The tls field in VirtualService is for routing based on SNI, not for terminating or requiring client certificates.

  • ✓

    Create a PeerAuthentication resource with mtls.mode: STRICT

    Why this is correct

    PeerAuthentication is a native Istio security policy that defines how sidecar proxies accept inbound traffic. Setting mtls.mode: STRICT enforces that the server side requires mutual TLS, rejecting any plaintext or non-mutual TLS requests. This works at the sidecar proxy level and applies per namespace, workload, or globally through the mesh root, making it the canonical server-side enforcement mechanism.

  • ✗

    Set global.mtls.enabled: true in IstioConfigMap

    Why it's wrong here

    While Istio has a MeshConfig, there is no `global.mtls.enabled` field; the legacy configuration for global mutual TLS was removed in favor of explicit security policies. Even if a similar default were set, it would only establish a default for sidecar TLS settings, not actively enforce strict mTLS, and Istio's current best practice is to use PeerAuthentication and DestinationRule instead.

  • ✓

    Create a DestinationRule with tls.mode: ISTIO_MUTUAL

    Why this is correct

    DestinationRule is a client-side configuration that defines how traffic from a source sidecar is sent to a destination. Setting tls.mode: ISTIO_MUTUAL instructs the client sidecar to initiate mutual TLS using Istio's built-in certificates, ensuring the outgoing connection uses mTLS. This complements PeerAuthentication, which enforces the server side, and together they provide end-to-end mTLS for the service.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.