Courseiva
Cloud Native Architecture →mediumMultiple Choice

KCNA Cloud Native Architecture Practice Question

In a service mesh architecture, which component is responsible for intercepting and managing traffic to and from a pod?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sidecar proxy

The sidecar proxy (e.g., Envoy) runs alongside each service instance and intercepts all network traffic, enabling features like traffic management and observability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Sidecar proxy

    Why this is correct

    The sidecar proxy runs alongside each pod, intercepting inbound and outbound traffic at the pod level. It enforces the mesh's routing, mTLS and telemetry policies, which is why it, rather than the control plane, handles per-pod traffic management.

  • ✗

    Ingress controller

    Why it's wrong here

    An ingress controller routes external traffic into the cluster at the edge; it does not sit alongside each pod intercepting its inbound and outbound connections. It is tempting because both handle traffic entering workloads, yet the sidecar proxy, not the ingress layer, performs per-pod interception within the mesh.

  • ✗

    API gateway

    Why it's wrong here

    An API gateway manages north-south traffic between external clients and services, but it lacks the per-pod sidecar proxy needed to intercept and control east-west traffic within the mesh. This option is tempting because an API gateway also handles routing, authentication, and rate limiting for incoming requests, making it the correct choice when the question concerns external ingress rather than internal pod-to-pod communication.

  • ✗

    Control plane

    Why it's wrong here

    The control plane distributes configuration and policy to the mesh but never touches the data path, so it cannot intercept pod traffic. It is tempting because it governs proxies and certificates, and in a mesh it is the component administrators interact with most, yet interception is performed by the data plane sidecars.

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.