Courseiva

KCNA Cloud Native Architecture Practice Question

Which THREE of the following are features provided by a service mesh like Istio? (Select THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Traffic routing and load balancing

Service mesh provides traffic management (routing), observability (metrics, tracing), and security (mTLS, policies).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Container image building

    Why it's wrong here

    Container image building is performed by a container runtime or CI pipeline such as Docker, Buildah or Kaniko, producing OCI images before any workload reaches the cluster. Istio operates at the network layer, intercepting service-to-service traffic. Image building would be the correct concern when authoring and publishing application images.

  • ✓

    Traffic routing and load balancing

    Why this is correct

    Istio's control plane configures Envoy sidecars with routing rules, retries, timeouts and load-balancing algorithms, enabling canary releases and traffic shifting. This satisfies the traffic management requirement by directing and distributing requests across service instances independently of application code.

  • ✓

    Observability including metrics and distributed tracing

    Why this is correct

    Sidecar proxies emit uniform telemetry for every request, feeding Prometheus metrics and distributed traces through Jaeger or Zipkin without code changes. This satisfies the observability requirement by giving consistent latency, error and traffic visibility across heterogeneous services.

  • ✓

    Security through mTLS and access policies

    Why this is correct

    Istio's sidecar proxies enforce mutual TLS between workloads and evaluate authorisation policies on every request, delivering encryption and identity-based access control without application changes. This satisfies the security feature requirement by providing zero-trust service-to-service protection at the mesh layer.

  • ✗

    Database schema migrations

    Why it's wrong here

    Database schema migrations are handled by migration tooling such as Flyway or Liquibase, or application startup jobs, altering persistent state rather than service traffic. Istio manages mTLS, routing, retries and telemetry between workloads. Schema migration tooling would be the correct choice when evolving a relational database's structure.

About these practice questions

This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on KCNA

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are features of a service mesh like Istio or Linkerd? (Select 2)

hard
  • A.Container image building
  • ✓ B.Traffic management (routing, load balancing)
  • ✓ C.Observability (metrics, tracing, logs)
  • D.Service discovery
  • E.Auto-scaling of services

Why B: Option B is correct because a service mesh like Istio or Linkerd deploys sidecar proxies (Envoy in Istio, linkerd2-proxy in Linkerd) alongside each workload to intercept east-west traffic and provide fine-grained traffic management such as HTTP/gRPC routing, retries, timeouts, circuit breaking, and load balancing. Option C is correct because these sidecars also emit telemetry — request metrics (e.g., Prometheus-scraped latency/error counters), distributed traces (via Zipkin/Jaeger/OpenTelemetry), and access logs — giving uniform observability without changing application code. Option A is not a service mesh feature; container image building is handled by tools like Docker BuildKit, Buildah, or Kaniko in a CI pipeline. Option D, service discovery, is a related but distinct capability typically provided by the platform (Kubernetes Services/DNS, Consul) that the mesh consumes rather than being a defining feature of the mesh itself. Option E, auto-scaling, is performed by Kubernetes controllers such as the Horizontal Pod Autoscaler or KEDA, not by the service mesh data plane.

Variation 2. Which THREE of the following are features typically provided by a service mesh? (Choose three.)

hard
  • ✓ A.Observability through metrics and tracing
  • B.Auto-scaling of pods based on CPU
  • ✓ C.Traffic management between services
  • ✓ D.Security with mutual TLS (mTLS)
  • E.Service discovery

Why A: A service mesh like Istio or Linkerd provides observability by collecting metrics and distributed traces from the sidecar proxies (e.g., Envoy) that intercept service-to-service traffic, so option A is correct. It also delivers traffic management capabilities such as routing rules, retries, timeouts, circuit breaking, and canary or blue-green deployments, making option C correct. Additionally, a service mesh secures service-to-service communication with mutual TLS (mTLS), automatically issuing and rotating certificates and enforcing encryption and identity between workloads, so option D is correct. Option B is wrong because pod auto-scaling based on CPU is handled by the Kubernetes Horizontal Pod Autoscaler (HPA), not by a service mesh. Option E is wrong because service discovery is a core Kubernetes function (via kube-dns/CoreDNS and Services), not a feature typically attributed to the service mesh itself.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.