Courseiva
Cloud Native Architecture →mediumMultiple Choice

KCNA Cloud Native Architecture Practice Question

Which component in a service mesh is responsible for collecting telemetry data and enforcing traffic policies?

⚠ Common exam trap

The trap is confusing the control plane (which configures policy) with the data plane (which enforces it) — candidates often pick 'control plane' because it sounds like the brain of the mesh, but telemetry collection and runtime policy enforcement happen in the sidecar proxy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sidecar proxy (data plane)

In a service mesh, the sidecar proxy (part of the data plane) is the component that actually intercepts service-to-service traffic, enforces traffic policies (routing, retries, timeouts, mTLS), and emits telemetry (metrics, logs, traces) for each request. The control plane configures the sidecars but does not handle live traffic itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Control plane

    Why it's wrong here

    The control plane distributes configuration and policy to sidecars; the sidecars themselves generate telemetry and enforce those policies at the data path. The control plane is correct for questions about configuration distribution, certificate issuance or mesh-wide policy definition.

  • ✓

    Sidecar proxy (data plane)

    Why this is correct

    The sidecar proxy sits alongside each workload in the data plane, intercepting all inbound and outbound traffic. It enforces routing and access policies while emitting metrics, logs and traces to the control plane's telemetry collectors.

  • ✗

    Certificate authority

    Why it's wrong here

    A certificate authority issues and rotates workload identities for mutual TLS; it does not observe traffic or apply policy. Sidecar proxies collect telemetry and enforce traffic rules. The certificate authority is the right answer for questions about identity provisioning and key rotation within the mesh.

  • ✗

    Service mesh ingress gateway

    Why it's wrong here

    An ingress gateway handles north-south traffic entering the mesh, performing routing and TLS termination at the edge. Telemetry collection and per-pod policy enforcement happen in the sidecar proxies alongside each workload. The ingress gateway is correct when exposing internal services to external clients.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.