KCNA Cloud Native Architecture Practice Question
Which component of the Istio service mesh is responsible for certificate signing and identity management?
⚠ Common exam trap
KCNA often tests Istio component roles, and candidates confuse the data plane (Envoy) with control plane components (Citadel, Pilot, Mixer), picking Envoy because it 'handles security' via mTLS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Citadel
Citadel is the Istio component responsible for certificate signing, key management, and identity management, issuing SPIFFE-compliant identities to workloads. It acts as the certificate authority for the mesh, enabling mutual TLS between services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Envoy
Why it's wrong here
Envoy is the sidecar data-plane proxy that enforces mTLS and forwards traffic, but it does not sign certificates or manage identities; Citadel (Istiod) issues those workload certificates. Envoy is tempting because it terminates and originates mTLS connections, yet it merely consumes the certificates Istiod generates.
- ✓
Citadel
Why this is correct
Citadel handles certificate signing and identity management in Istio, issuing SPIFFE-based workload certificates to sidecar proxies and rotating them automatically. This satisfies the stem's requirement for the mesh component responsible for certificate signing and identity management, distinct from traffic-routing components such as Pilot or Envoy.
- ✗
Mixer
Why it's wrong here
Mixer enforced telemetry, policy and quota checks in older Istio releases; certificate signing and workload identity are handled by Citadel (now istiod). It is tempting because Mixer sat centrally in the control plane, but it never issued or rotated SPIFFE certificates for workloads.
- ✗
Pilot
Why it's wrong here
Pilot distributes routing and traffic-management configuration to Envoy sidecars; it does not perform certificate signing or identity management, which Citadel (now within Istiod) handles. Pilot is tempting because it is a core control-plane component, but its role is service discovery and traffic policy, not workload identity.
Go deeper
Related to this question
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.