Courseiva
Security Architecture →hardMultiple Select

CAS-004 Security Architecture Practice Question

A security architect is designing a microservices-based application deployed on containers in a Kubernetes cluster. The architect needs to implement controls that protect the application from lateral movement in case a container is compromised. Which TWO of the following controls best achieve this goal? (Choose two.)

⚠ Common exam trap

The trap here is assuming that any security control, such as RBAC, automatically prevents lateral movement, when in fact lateral movement is primarily a network communication issue that requires network segmentation or service mesh authorization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a service mesh to enforce mutual TLS (mTLS) between all services and apply authorization policies based on service identity.

Default-deny network policies restrict pod-to-pod traffic to only what is explicitly allowed, and a service mesh with mutual TLS and authorization policies enforces identity-based communication between services. Together, these controls limit an attacker's ability to move laterally from a compromised container. RBAC, privileged containers, and secrets in environment variables do not prevent network-based lateral movement and may even increase risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a service mesh to enforce mutual TLS (mTLS) between all services and apply authorization policies based on service identity.

    Why this is correct

    A service mesh with mutual TLS authenticates and encrypts all service-to-service communication, and authorization policies can restrict which services are allowed to talk to each other based on identity. If a container is compromised, the attacker cannot impersonate another service or communicate with services that are not explicitly authorized, which significantly limits lateral movement. This is a strong control for microservices environments.

  • ✗

    Enable role-based access control (RBAC) for the Kubernetes API and grant each service account the minimum permissions required.

    Why it's wrong here

    RBAC limits what actions a compromised pod can perform against the Kubernetes API, such as listing secrets or creating pods. While important for defense in depth, it does not prevent network-based lateral movement between pods. An attacker could still communicate with other services over the network even with restricted API permissions. Therefore, it is not one of the two best controls for preventing lateral movement.

  • ✓

    Implement network policies that deny all ingress and egress traffic by default and allow only explicitly required communication between specific pods.

    Why this is correct

    Default-deny network policies in Kubernetes restrict pod-to-pod communication to only what is explicitly allowed. If a container is compromised, the attacker cannot freely scan or connect to other services, which limits lateral movement. This is a fundamental microsegmentation control for containerized environments and directly addresses the goal of containing a breach.

  • ✗

    Store all application secrets in environment variables within the container images to simplify deployment.

    Why it's wrong here

    Storing secrets in environment variables or container images exposes them to anyone who can inspect the image or the running container. If a container is compromised, the attacker can read these secrets and use them to access other services, facilitating lateral movement. This practice weakens security and does not prevent lateral movement; it enables it.

  • ✗

    Run all containers as privileged to ensure they have the necessary permissions to perform their functions.

    Why it's wrong here

    Running containers as privileged gives them almost unrestricted access to the host and other containers, which greatly increases the impact of a compromise. A privileged container can often escape to the host and then move laterally to other nodes. This is the opposite of a security best practice and would not limit lateral movement; it would enable it.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.