Courseiva
Security Engineering →hardMultiple Select

CAS-004 Security Engineering Practice Question

A security architect is designing a microservices-based application deployed on a Kubernetes cluster. The architect needs to ensure that inter-service communication is secure, that services can authenticate each other, and that access to services is controlled based on identity. Which TWO of the following should be implemented? (Choose two.)

⚠ Common exam trap

The trap here is thinking that network segmentation or static secrets alone can provide authentication and authorization for microservices, when identity-based controls are required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mutual TLS (mTLS) between services using short-lived certificates

Mutual TLS with short-lived certificates ensures encrypted and authenticated communication between services, while a service mesh with identity-based authorization policies provides centralized, fine-grained access control based on service identity. Together, they secure inter-service communication and enforce access control. The other options either lack encryption, use static secrets, or are overly permissive.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A shared secret used by all services for authentication

    Why it's wrong here

    A shared secret used by all services means that any compromised service can impersonate any other, violating the principle of least privilege and lacking non-repudiation. It also does not encrypt traffic. This approach is insecure and does not meet the requirements for mutual authentication and identity-based access control.

  • ✗

    API keys stored in environment variables for each service

    Why it's wrong here

    API keys stored in environment variables are static secrets that can be leaked and do not provide mutual authentication. They also do not encrypt traffic. While they can be used for authorization, they are not suitable for secure service-to-service communication and identity-based access control in a dynamic microservices environment.

  • ✗

    Network policies that allow all traffic within the cluster namespace

    Why it's wrong here

    Allowing all traffic within a namespace does not provide authentication or encryption, and it violates the principle of least privilege. While network policies can segment traffic, this configuration is overly permissive and does not control access based on service identity. It fails to meet the requirement for controlled access based on identity.

  • ✓

    Mutual TLS (mTLS) between services using short-lived certificates

    Why this is correct

    Mutual TLS with short-lived certificates provides strong authentication and encryption for inter-service communication. Short-lived certificates reduce the risk of key compromise and enable automatic rotation. This ensures that only authenticated services can communicate, and all traffic is encrypted, meeting the requirements for secure service-to-service communication.

  • ✓

    A service mesh with identity-based authorization policies

    Why this is correct

    A service mesh provides identity-based authentication and authorization for services, often using mTLS and policy enforcement. It centralizes control and allows fine-grained access policies based on service identity. This meets the requirements for secure communication and identity-based access control in a microservices environment.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.