Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

A financial services firm runs its customer portal on a Kubernetes cluster in AWS. During a penetration test, an attacker who compromised a front-end pod moved laterally to a database pod by directly connecting to its IP address, even though no NetworkPolicy existed. The security architect must implement a control that enforces least-privilege communication between pods and blocks all unauthorized east-west traffic by default. Which of the following should the architect implement?

⚠ Common exam trap

The trap here is assuming that encrypting service traffic with mutual TLS automatically prevents lateral movement, when authorization policy is what actually denies unauthorized connections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a Kubernetes NetworkPolicy with a default-deny ingress rule and explicit allow rules for required pod-to-pod flows.

The requirement is to enforce least-privilege pod-to-pod communication and block unauthorized east-west traffic by default. Kubernetes NetworkPolicy is the native control that operates at the pod level and can implement a default-deny posture with explicit allow rules. Node-level Security Groups and egress gateways do not provide pod-level segmentation, and mTLS without authorization policy does not deny connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable AWS Security Groups for the worker nodes and restrict inbound rules to the node CIDR block.

    Why it's wrong here

    Security Groups operate at the EC2 instance level, not the pod level. Pods on the same node share the node's network namespace and Security Group, so intra-node pod-to-pod traffic is not isolated. This control would not block the attacker's lateral move between pods on the same node and fails to provide least-privilege pod segmentation.

  • ✗

    Deploy a service mesh sidecar proxy and enforce mutual TLS between all services.

    Why it's wrong here

    Mutual TLS authenticates and encrypts service-to-service traffic but does not by itself deny unauthorized connections. Without an authorization policy, a compromised pod can still establish an mTLS session with the database pod if it possesses a valid certificate. The scenario requires default-deny enforcement, which mTLS alone does not provide.

  • ✗

    Apply egress-only internet gateway rules to prevent pods from reaching external networks.

    Why it's wrong here

    An egress-only internet gateway controls outbound IPv6 traffic to the internet, not internal pod-to-pod communication. The attack was east-west within the cluster, so restricting external egress does nothing to stop the database pod from being reached. This control addresses a different threat vector and leaves lateral movement unmitigated.

  • ✓

    Configure a Kubernetes NetworkPolicy with a default-deny ingress rule and explicit allow rules for required pod-to-pod flows.

    Why this is correct

    NetworkPolicy is the native Kubernetes mechanism to enforce pod-level segmentation. A default-deny ingress policy blocks all traffic not explicitly allowed, satisfying least privilege and stopping lateral movement. Explicit allow rules then permit only the required database access from the front end. This directly addresses the scenario's requirement to block unauthorized east-west traffic without adding external components.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.