Courseiva
hardMultiple Choice

CAS-004 Practice Question: Migrating from a legacy three-tier architecture…

A company is migrating from a legacy three-tier architecture to a microservices architecture on Kubernetes. The security team wants to ensure that service-to-service communication is encrypted and mutually authenticated. Which approach best meets these requirements with minimal operational overhead?

⚠ Common exam trap

Many candidates choose IPsec or VPN solutions because they are familiar with network-layer encryption, but they fail to recognize that these approaches do not scale to the dynamic, ephemeral nature of microservices and introduce prohibitive operational overhead compared to a service mesh's automated mTLS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a service mesh with mutual TLS (mTLS) and automatic certificate management.

A service mesh with mutual TLS (mTLS) and automatic certificate management is the correct approach because it provides encrypted, mutually authenticated service-to-service communication with minimal operational overhead. The service mesh (e.g., Istio, Linkerd) transparently intercepts traffic via sidecar proxies, handles mTLS handshakes, and automates certificate issuance and rotation, eliminating the need for manual key distribution or application-level changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement a service mesh with mutual TLS (mTLS) and automatic certificate management.

    Why this is correct

    A service mesh with mTLS encrypts all service-to-service traffic and authenticates both endpoints via certificates, satisfying the mutual authentication requirement. Its control plane automates certificate issuance and rotation across Kubernetes pods, delivering this with minimal operational overhead compared with manually managing certificates per service.

  • ✗

    Deploy IPsec tunnels between each pair of services using pre-shared keys.

    Why it's wrong here

    IPsec with pre-shared keys encrypts traffic but authenticates hosts, not workloads, and PSK distribution across every service pair scales poorly. It is tempting because IPsec is a proven encryption mechanism, yet it cannot express Kubernetes service identity, which a service mesh's mTLS handles natively.

  • ✗

    Establish a site-to-site VPN between the Kubernetes cluster and the legacy network, and route all service traffic through the VPN.

    Why it's wrong here

    A site-to-site VPN secures traffic between the cluster and legacy network, not communication between individual services inside the cluster. It is tempting because VPNs encrypt transit, but east-west pod traffic never leaves the cluster, so the tunnel addresses the wrong path and adds no mutual authentication.

  • ✗

    Configure each service to use TLS with self-signed certificates, and distribute the CA certificate to all services.

    Why it's wrong here

    Self-signed certificates require manual issuance, rotation and CA distribution across every service, creating heavy operational overhead and no automatic identity. It is tempting because TLS provides encryption and mutual authentication, but a service mesh with automatic certificate rotation delivers both with far less manual effort.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.