KCNA Cloud Native Architecture Practice Question
Which component in a service mesh is responsible for collecting telemetry data and enforcing traffic policies?
⚠ Common exam trap
The trap is confusing the control plane (which configures policy) with the data plane (which enforces it) — candidates often pick 'control plane' because it sounds like the brain of the mesh, but telemetry collection and runtime policy enforcement happen in the sidecar proxy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sidecar proxy (data plane)
In a service mesh, the sidecar proxy (part of the data plane) is the component that actually intercepts service-to-service traffic, enforces traffic policies (routing, retries, timeouts, mTLS), and emits telemetry (metrics, logs, traces) for each request. The control plane configures the sidecars but does not handle live traffic itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Control plane
Why it's wrong here
The control plane distributes configuration and policy to sidecars; the sidecars themselves generate telemetry and enforce those policies at the data path. The control plane is correct for questions about configuration distribution, certificate issuance or mesh-wide policy definition.
- ✓
Sidecar proxy (data plane)
Why this is correct
The sidecar proxy sits alongside each workload in the data plane, intercepting all inbound and outbound traffic. It enforces routing and access policies while emitting metrics, logs and traces to the control plane's telemetry collectors.
- ✗
Certificate authority
Why it's wrong here
A certificate authority issues and rotates workload identities for mutual TLS; it does not observe traffic or apply policy. Sidecar proxies collect telemetry and enforce traffic rules. The certificate authority is the right answer for questions about identity provisioning and key rotation within the mesh.
- ✗
Service mesh ingress gateway
Why it's wrong here
An ingress gateway handles north-south traffic entering the mesh, performing routing and TLS termination at the edge. Telemetry collection and per-pod policy enforcement happen in the sidecar proxies alongside each workload. The ingress gateway is correct when exposing internal services to external clients.
Go deeper
Related to this question
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.