CAS-004 Security Architecture Practice Question
A security architect at a financial services firm is designing the network for a new containerized trading platform. The platform must enforce Layer 7 policy, provide mutual TLS between all microservices, and eliminate the need to reconfigure each application for cryptographic identity. Which architecture should the architect implement?
⚠ Common exam trap
The trap here is assuming an API gateway can secure east-west microservice traffic, when it is primarily designed for north-south ingress traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A service mesh that uses sidecar proxies to intercept all service-to-service traffic and perform mutual TLS
The service mesh architecture uses sidecar proxies to intercept all service-to-service communication, enabling transparent mutual TLS and Layer 7 policy enforcement without modifying application code. This satisfies the demand for cryptographic identity across microservices and eliminates per-application reconfiguration, making it the appropriate design for a containerized trading platform.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A VPN concentrator that creates an encrypted overlay network between all container hosts
Why it's wrong here
A VPN concentrator encrypts host-to-host traffic, but it authenticates hosts rather than individual microservices. It does not provide per-service cryptographic identity, nor does it enforce Layer 7 policy. Reconfiguring each application to participate in the VPN would still be necessary, which the requirement explicitly seeks to avoid.
- ✗
A network intrusion prevention system (NIPS) deployed inline at the cluster edge
Why it's wrong here
A NIPS inspects network traffic for malicious patterns but does not provide cryptographic identity or mutual TLS between services. It operates at the network perimeter, not as an in-cluster identity mechanism. It also cannot enforce application-layer authorization policies for each microservice call.
- ✗
An API gateway that terminates TLS and routes requests to backend microservices
Why it's wrong here
An API gateway typically handles north-south traffic entering the cluster, not east-west traffic between microservices. It does not automatically enforce mutual TLS for service-to-service calls, and applications would still need to be configured to trust the gateway. The requirement for pervasive Layer 7 policy across all microservices is not met.
- ✓
A service mesh that uses sidecar proxies to intercept all service-to-service traffic and perform mutual TLS
Why this is correct
A service mesh with sidecar proxies transparently intercepts pod traffic, enforces Layer 7 policy, and performs mutual TLS without application code changes, satisfying all three requirements in this scenario. It centralizes cryptographic identity through the control plane, so each microservice does not need to be reconfigured individually.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.