CAS-004 Security Architecture Practice Question
A security architect is designing a defense-in-depth strategy for a cloud-native application. Which TWO controls are most effective for protecting east-west traffic between microservices?
⚠ Common exam trap
CAS-005 often tests the distinction between north-south and east-west controls; candidates frequently select perimeter tools like WAF or gateway IDS, which do not address internal microservice traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Service mesh with mutual TLS
Option A (Service mesh with mutual TLS) is correct because a service mesh provides identity-based, encrypted, and authenticated communication between microservices, and mutual TLS ensures both sides of an east-west connection verify each other's certificates, preventing spoofing and eavesdropping inside the cluster. Option C (Micro-segmentation of virtual networks) is correct because it enforces least-privilege reachability between workloads by applying granular policies at the virtual network or workload level, which directly limits lateral movement if a microservice is compromised. Option B is not the best fit because an IDS on the gateway monitors north-south traffic entering the environment rather than internal service-to-service flows, and it is detective rather than preventive. Option D is not appropriate because a WAF protects HTTP/HTTPS applications from external web attacks at the edge, not east-west microservice traffic. Option E is not appropriate because perimeter ACLs filter traffic at the network boundary and do not provide the identity-aware, workload-level controls needed for internal microservice communication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Service mesh with mutual TLS
Why this is correct
Mutual TLS in a service mesh authenticates and encrypts every service-to-service call, giving cryptographic workload identity rather than relying on network location. This directly protects east-west traffic inside the cluster, where perimeter controls cannot inspect lateral microservice communication.
- ✗
Intrusion detection system (IDS) on the gateway
Why it's wrong here
An IDS on the gateway inspects north-south traffic entering or leaving the environment, not east-west flows between microservices. It is tempting because gateway IDS is standard perimeter defence, and would be correct for detecting attacks crossing the boundary of a traditional network.
- ✓
Micro-segmentation of virtual networks
Why this is correct
Micro-segmentation applies granular allow-list rules between individual workloads, so a compromised microservice cannot reach unrelated services. It constrains lateral movement across east-west paths, satisfying the requirement to protect internal microservice traffic rather than only north-south ingress.
- ✗
Web application firewall (WAF)
Why it's wrong here
A WAF filters HTTP requests at the application edge, addressing north-south web attacks rather than east-west microservice traffic. It is tempting because WAFs are core application security controls, and would be correct for protecting an internet-facing web application from injection and similar attacks.
- ✗
Network access control lists (ACLs) at the perimeter
Why it's wrong here
Perimeter ACLs filter north-south traffic entering the network boundary, not the east-west flows between microservices inside the cluster. They are tempting because ACLs do enforce packet-level allow/deny rules, but that role belongs at the network edge, not between internal workloads.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.