KCNA Cloud Native Architecture Practice Question
Which THREE of the following are features provided by a service mesh like Istio? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Traffic routing and load balancing
Service mesh provides traffic management (routing), observability (metrics, tracing), and security (mTLS, policies).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Container image building
Why it's wrong here
Container image building is performed by a container runtime or CI pipeline such as Docker, Buildah or Kaniko, producing OCI images before any workload reaches the cluster. Istio operates at the network layer, intercepting service-to-service traffic. Image building would be the correct concern when authoring and publishing application images.
- ✓
Traffic routing and load balancing
Why this is correct
Istio's control plane configures Envoy sidecars with routing rules, retries, timeouts and load-balancing algorithms, enabling canary releases and traffic shifting. This satisfies the traffic management requirement by directing and distributing requests across service instances independently of application code.
- ✓
Observability including metrics and distributed tracing
Why this is correct
Sidecar proxies emit uniform telemetry for every request, feeding Prometheus metrics and distributed traces through Jaeger or Zipkin without code changes. This satisfies the observability requirement by giving consistent latency, error and traffic visibility across heterogeneous services.
- ✓
Security through mTLS and access policies
Why this is correct
Istio's sidecar proxies enforce mutual TLS between workloads and evaluate authorisation policies on every request, delivering encryption and identity-based access control without application changes. This satisfies the security feature requirement by providing zero-trust service-to-service protection at the mesh layer.
- ✗
Database schema migrations
Why it's wrong here
Database schema migrations are handled by migration tooling such as Flyway or Liquibase, or application startup jobs, altering persistent state rather than service traffic. Istio manages mTLS, routing, retries and telemetry between workloads. Schema migration tooling would be the correct choice when evolving a relational database's structure.
Go deeper
Related to this question
Learn chapter
Observability: Monitoring, Logging, and Tracing
Key term
Service Mesh
A service mesh is a dedicated infrastructure layer that manages communication between microservices, handling tasks like service discovery, load balancing, encryption, and observability without requiring changes to application code.
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on KCNA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are features of a service mesh like Istio or Linkerd? (Select 2)
hard- A.Container image building
- ✓ B.Traffic management (routing, load balancing)
- ✓ C.Observability (metrics, tracing, logs)
- D.Service discovery
- E.Auto-scaling of services
Why B: Option B is correct because a service mesh like Istio or Linkerd deploys sidecar proxies (Envoy in Istio, linkerd2-proxy in Linkerd) alongside each workload to intercept east-west traffic and provide fine-grained traffic management such as HTTP/gRPC routing, retries, timeouts, circuit breaking, and load balancing. Option C is correct because these sidecars also emit telemetry — request metrics (e.g., Prometheus-scraped latency/error counters), distributed traces (via Zipkin/Jaeger/OpenTelemetry), and access logs — giving uniform observability without changing application code. Option A is not a service mesh feature; container image building is handled by tools like Docker BuildKit, Buildah, or Kaniko in a CI pipeline. Option D, service discovery, is a related but distinct capability typically provided by the platform (Kubernetes Services/DNS, Consul) that the mesh consumes rather than being a defining feature of the mesh itself. Option E, auto-scaling, is performed by Kubernetes controllers such as the Horizontal Pod Autoscaler or KEDA, not by the service mesh data plane.
Variation 2. Which THREE of the following are features typically provided by a service mesh? (Choose three.)
hard- ✓ A.Observability through metrics and tracing
- B.Auto-scaling of pods based on CPU
- ✓ C.Traffic management between services
- ✓ D.Security with mutual TLS (mTLS)
- E.Service discovery
Why A: A service mesh like Istio or Linkerd provides observability by collecting metrics and distributed traces from the sidecar proxies (e.g., Envoy) that intercept service-to-service traffic, so option A is correct. It also delivers traffic management capabilities such as routing rules, retries, timeouts, circuit breaking, and canary or blue-green deployments, making option C correct. Additionally, a service mesh secures service-to-service communication with mutual TLS (mTLS), automatically issuing and rotating certificates and enforcing encryption and identity between workloads, so option D is correct. Option B is wrong because pod auto-scaling based on CPU is handled by the Kubernetes Horizontal Pod Autoscaler (HPA), not by a service mesh. Option E is wrong because service discovery is a core Kubernetes function (via kube-dns/CoreDNS and Services), not a feature typically attributed to the service mesh itself.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.