Courseiva

KCNA Cloud Native Architecture Practice Question

Which Kubernetes resource is commonly used to implement the sidecar pattern for injecting a service mesh proxy?

⚠ Common exam trap

CNCF often tests the misconception that a Service or NetworkPolicy is responsible for sidecar injection, when in fact only a mutating admission webhook can automatically modify Pod specs at creation time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

MutatingAdmissionWebhook

A MutatingAdmissionWebhook intercepts Pod creation requests and automatically injects a sidecar container (e.g., Envoy or Linkerd-proxy) into the Pod spec. This is the standard mechanism used by service mesh control planes like Istio and Linkerd to transparently add the proxy without modifying application manifests.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    NetworkPolicy

    Why it's wrong here

    NetworkPolicy governs ingress and egress traffic rules for selected pods; it cannot inject a proxy container into a pod template. It is tempting because service meshes enforce traffic policy, and a NetworkPolicy would be the right resource when restricting which pods may communicate with a mesh workload.

  • ✗

    Service

    Why it's wrong here

    A Service provides stable network access to a set of pods; it does not add a container to a pod's specification, which sidecar injection requires. It is tempting because service mesh proxies route traffic between services, and a Service would be the right resource when exposing the mesh-enabled workload to callers.

  • ✓

    MutatingAdmissionWebhook

    Why this is correct

    A MutatingAdmissionWebhook intercepts pod creation requests and mutates the pod specification, which is how sidecar containers such as service mesh proxies are injected automatically. This admission-time mutation mechanism is the standard implementation of sidecar injection in Kubernetes.

  • ✗

    ConfigMap

    Why it's wrong here

    ConfigMap stores configuration data as key-value pairs for pods to consume; it cannot inject a container into a pod, which the sidecar pattern requires. It is tempting because sidecar proxies are configured through mounted configuration, and a ConfigMap would be the right resource when supplying proxy settings to an already-injected container.

Go deeper

Related to this question

About these practice questions

This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.