KCNA Cloud Native Architecture Practice Question
What is the primary purpose of a service mesh in a cloud-native architecture?
⚠ Common exam trap
KCNA often tests the confusion between service mesh and container orchestration, leading candidates to think a service mesh replaces Kubernetes or handles scaling, when it actually focuses on communication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To provide a dedicated infrastructure layer for handling service-to-service communication
A service mesh provides a dedicated infrastructure layer for managing service-to-service communication, typically using sidecar proxies. It handles traffic management, security, and observability without requiring changes to application code. This allows developers to focus on business logic while the mesh handles cross-cutting concerns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To compile application code
Why it's wrong here
Compilation happens in build toolchains and CI pipelines, producing binaries or container images before deployment. A service mesh operates at runtime, intercepting pod-to-pod traffic via sidecar proxies to enforce mTLS, retries and traffic splitting. It is tempting because meshes are configured declaratively, but that configuration governs network behaviour, not source code translation.
- ✓
To provide a dedicated infrastructure layer for handling service-to-service communication
Why this is correct
A service mesh supplies a dedicated infrastructure layer, typically via sidecar proxies, that handles service-to-service communication concerns such as traffic routing, mutual TLS, retries and observability. This offloads those functions from application code, satisfying the cloud-native communication requirement.
- ✗
To replace container orchestration
Why it's wrong here
A service mesh provides traffic management, mutual TLS, observability and policy between services; it runs alongside orchestration rather than replacing it. Replacing container orchestration is not its function — Kubernetes still schedules and runs the workloads.
- ✗
To store application configuration
Why it's wrong here
Configuration storage belongs to ConfigMaps, Secrets or a dedicated configuration service, not the mesh data plane. A service mesh governs east-west traffic through sidecar proxies, providing mTLS, retries, traffic splitting and observability between workloads. It is tempting because meshes do expose policy configuration, but that configures routing, not application settings.
Go deeper
Related to this question
Learn chapter
Cloud Native Architecture and Concepts
Key term
Service Mesh
A service mesh is a dedicated infrastructure layer that manages communication between microservices, handling tasks like service discovery, load balancing, encryption, and observability without requiring changes to application code.
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.