Courseiva
Cloud Native Architecture →mediumMultiple Choice

KCNA Cloud Native Architecture Practice Question

Which component of the Istio service mesh is responsible for certificate signing and identity management?

⚠ Common exam trap

KCNA often tests Istio component roles, and candidates confuse the data plane (Envoy) with control plane components (Citadel, Pilot, Mixer), picking Envoy because it 'handles security' via mTLS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Citadel

Citadel is the Istio component responsible for certificate signing, key management, and identity management, issuing SPIFFE-compliant identities to workloads. It acts as the certificate authority for the mesh, enabling mutual TLS between services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Envoy

    Why it's wrong here

    Envoy is the sidecar data-plane proxy that enforces mTLS and forwards traffic, but it does not sign certificates or manage identities; Citadel (Istiod) issues those workload certificates. Envoy is tempting because it terminates and originates mTLS connections, yet it merely consumes the certificates Istiod generates.

  • ✓

    Citadel

    Why this is correct

    Citadel handles certificate signing and identity management in Istio, issuing SPIFFE-based workload certificates to sidecar proxies and rotating them automatically. This satisfies the stem's requirement for the mesh component responsible for certificate signing and identity management, distinct from traffic-routing components such as Pilot or Envoy.

  • ✗

    Mixer

    Why it's wrong here

    Mixer enforced telemetry, policy and quota checks in older Istio releases; certificate signing and workload identity are handled by Citadel (now istiod). It is tempting because Mixer sat centrally in the control plane, but it never issued or rotated SPIFFE certificates for workloads.

  • ✗

    Pilot

    Why it's wrong here

    Pilot distributes routing and traffic-management configuration to Envoy sidecars; it does not perform certificate signing or identity management, which Citadel (now within Istiod) handles. Pilot is tempting because it is a core control-plane component, but its role is service discovery and traffic policy, not workload identity.

About these practice questions

This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.