Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

A security architect at a financial services firm is designing the network for a new containerized trading platform. The platform must enforce Layer 7 policy, provide mutual TLS between all microservices, and eliminate the need to reconfigure each application for cryptographic identity. Which architecture should the architect implement?

⚠ Common exam trap

The trap here is assuming an API gateway can secure east-west microservice traffic, when it is primarily designed for north-south ingress traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A service mesh that uses sidecar proxies to intercept all service-to-service traffic and perform mutual TLS

The service mesh architecture uses sidecar proxies to intercept all service-to-service communication, enabling transparent mutual TLS and Layer 7 policy enforcement without modifying application code. This satisfies the demand for cryptographic identity across microservices and eliminates per-application reconfiguration, making it the appropriate design for a containerized trading platform.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A VPN concentrator that creates an encrypted overlay network between all container hosts

    Why it's wrong here

    A VPN concentrator encrypts host-to-host traffic, but it authenticates hosts rather than individual microservices. It does not provide per-service cryptographic identity, nor does it enforce Layer 7 policy. Reconfiguring each application to participate in the VPN would still be necessary, which the requirement explicitly seeks to avoid.

  • ✗

    A network intrusion prevention system (NIPS) deployed inline at the cluster edge

    Why it's wrong here

    A NIPS inspects network traffic for malicious patterns but does not provide cryptographic identity or mutual TLS between services. It operates at the network perimeter, not as an in-cluster identity mechanism. It also cannot enforce application-layer authorization policies for each microservice call.

  • ✗

    An API gateway that terminates TLS and routes requests to backend microservices

    Why it's wrong here

    An API gateway typically handles north-south traffic entering the cluster, not east-west traffic between microservices. It does not automatically enforce mutual TLS for service-to-service calls, and applications would still need to be configured to trust the gateway. The requirement for pervasive Layer 7 policy across all microservices is not met.

  • ✓

    A service mesh that uses sidecar proxies to intercept all service-to-service traffic and perform mutual TLS

    Why this is correct

    A service mesh with sidecar proxies transparently intercepts pod traffic, enforces Layer 7 policy, and performs mutual TLS without application code changes, satisfying all three requirements in this scenario. It centralizes cryptographic identity through the control plane, so each microservice does not need to be reconfigured individually.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.