Courseiva
Security Architecture →mediumMultiple Select

CAS-004 Security Architecture Practice Question

A security architect is designing a defense-in-depth strategy for a cloud-native application. Which TWO controls are most effective for protecting east-west traffic between microservices?

⚠ Common exam trap

CAS-005 often tests the distinction between north-south and east-west controls; candidates frequently select perimeter tools like WAF or gateway IDS, which do not address internal microservice traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Service mesh with mutual TLS

Option A (Service mesh with mutual TLS) is correct because a service mesh provides identity-based, encrypted, and authenticated communication between microservices, and mutual TLS ensures both sides of an east-west connection verify each other's certificates, preventing spoofing and eavesdropping inside the cluster. Option C (Micro-segmentation of virtual networks) is correct because it enforces least-privilege reachability between workloads by applying granular policies at the virtual network or workload level, which directly limits lateral movement if a microservice is compromised. Option B is not the best fit because an IDS on the gateway monitors north-south traffic entering the environment rather than internal service-to-service flows, and it is detective rather than preventive. Option D is not appropriate because a WAF protects HTTP/HTTPS applications from external web attacks at the edge, not east-west microservice traffic. Option E is not appropriate because perimeter ACLs filter traffic at the network boundary and do not provide the identity-aware, workload-level controls needed for internal microservice communication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Service mesh with mutual TLS

    Why this is correct

    Mutual TLS in a service mesh authenticates and encrypts every service-to-service call, giving cryptographic workload identity rather than relying on network location. This directly protects east-west traffic inside the cluster, where perimeter controls cannot inspect lateral microservice communication.

  • ✗

    Intrusion detection system (IDS) on the gateway

    Why it's wrong here

    An IDS on the gateway inspects north-south traffic entering or leaving the environment, not east-west flows between microservices. It is tempting because gateway IDS is standard perimeter defence, and would be correct for detecting attacks crossing the boundary of a traditional network.

  • ✓

    Micro-segmentation of virtual networks

    Why this is correct

    Micro-segmentation applies granular allow-list rules between individual workloads, so a compromised microservice cannot reach unrelated services. It constrains lateral movement across east-west paths, satisfying the requirement to protect internal microservice traffic rather than only north-south ingress.

  • ✗

    Web application firewall (WAF)

    Why it's wrong here

    A WAF filters HTTP requests at the application edge, addressing north-south web attacks rather than east-west microservice traffic. It is tempting because WAFs are core application security controls, and would be correct for protecting an internet-facing web application from injection and similar attacks.

  • ✗

    Network access control lists (ACLs) at the perimeter

    Why it's wrong here

    Perimeter ACLs filter north-south traffic entering the network boundary, not the east-west flows between microservices inside the cluster. They are tempting because ACLs do enforce packet-level allow/deny rules, but that role belongs at the network edge, not between internal workloads.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.