KCNA Cloud Native Architecture Practice Question
Which Kubernetes resource is commonly used to implement the sidecar pattern for injecting a service mesh proxy?
⚠ Common exam trap
CNCF often tests the misconception that a Service or NetworkPolicy is responsible for sidecar injection, when in fact only a mutating admission webhook can automatically modify Pod specs at creation time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MutatingAdmissionWebhook
A MutatingAdmissionWebhook intercepts Pod creation requests and automatically injects a sidecar container (e.g., Envoy or Linkerd-proxy) into the Pod spec. This is the standard mechanism used by service mesh control planes like Istio and Linkerd to transparently add the proxy without modifying application manifests.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
NetworkPolicy
Why it's wrong here
NetworkPolicy governs ingress and egress traffic rules for selected pods; it cannot inject a proxy container into a pod template. It is tempting because service meshes enforce traffic policy, and a NetworkPolicy would be the right resource when restricting which pods may communicate with a mesh workload.
- ✗
Service
Why it's wrong here
A Service provides stable network access to a set of pods; it does not add a container to a pod's specification, which sidecar injection requires. It is tempting because service mesh proxies route traffic between services, and a Service would be the right resource when exposing the mesh-enabled workload to callers.
- ✓
MutatingAdmissionWebhook
Why this is correct
A MutatingAdmissionWebhook intercepts pod creation requests and mutates the pod specification, which is how sidecar containers such as service mesh proxies are injected automatically. This admission-time mutation mechanism is the standard implementation of sidecar injection in Kubernetes.
- ✗
ConfigMap
Why it's wrong here
ConfigMap stores configuration data as key-value pairs for pods to consume; it cannot inject a container into a pod, which the sidecar pattern requires. It is tempting because sidecar proxies are configured through mounted configuration, and a ConfigMap would be the right resource when supplying proxy settings to an already-injected container.
Go deeper
Related to this question
Learn chapter
Cloud Native Application Design Principles
Key term
ReplicaSet and Replication
A ReplicaSet ensures a specified number of identical pod instances are running at all times in Kubernetes, using replication to maintain availability and stability.
Key term
Service Mesh
A service mesh is a dedicated infrastructure layer that manages communication between microservices, handling tasks like service discovery, load balancing, encryption, and observability without requiring changes to application code.
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.