CAS-004 Security Engineering Practice Question
A security architect is designing a network segmentation scheme for a containerized workload running on a Kubernetes cluster. The requirement is to enforce least-privilege communication between microservices at Layer 3 and Layer 4, and to ensure that only explicitly allowed traffic can flow between pods, even within the same namespace. Which of the following should the architect implement?
⚠ Common exam trap
It's easy for candidates to confuse service mesh mTLS, which provides encryption and identity, with network segmentation, which controls reachability; mTLS alone does not restrict which services can connect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kubernetes Network Policies with a default-deny ingress and egress policy.
To enforce least-privilege communication between microservices at Layer 3 and Layer 4, the architect needs a mechanism that controls pod-to-pod traffic based on labels and ports. Kubernetes Network Policies with a default-deny stance provide exactly that: a whitelist model where only explicitly permitted flows are allowed. This prevents unauthorized lateral movement even within the same namespace and is the native, CNI-supported solution for microsegmentation in Kubernetes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pod Security Admission with the restricted profile applied to all namespaces.
Why it's wrong here
Pod Security Admission controls the security context of pods, such as whether they run as privileged or can access the host network. It does not govern network traffic between pods. Applying the restricted profile improves the security posture of individual pods but does nothing to enforce which pods can talk to each other, so it fails to meet the segmentation requirement.
- ✗
A web application firewall (WAF) placed in front of the ingress controller.
Why it's wrong here
A WAF inspects HTTP/HTTPS traffic at Layer 7 for malicious payloads and attacks like SQL injection. It is not designed to enforce pod-to-pod communication policies or to segment traffic within the cluster. It also only covers traffic entering through the ingress, leaving east-west traffic between microservices uncontrolled, which is the primary concern in this scenario.
- ✗
Istio service mesh with mutual TLS (mTLS) enabled between all sidecars.
Why it's wrong here
Istio with mTLS provides strong identity-based authentication and encryption for service-to-service communication, but it does not by itself enforce Layer 3/Layer 4 network segmentation. Without authorization policies, any service with a valid certificate can still communicate with any other service. While Istio can enforce L7 policies, the requirement specifically asks for L3/L4 least privilege, which is better addressed by network policies.
- ✓
Kubernetes Network Policies with a default-deny ingress and egress policy.
Why this is correct
Kubernetes Network Policies are the native mechanism to control pod-to-pod traffic at Layer 3 and Layer 4. By applying a default-deny policy for both ingress and egress in a namespace, all traffic is blocked unless explicitly allowed by a subsequent policy. This enforces least privilege and prevents lateral movement between microservices. It works with a CNI plugin that supports network policies, such as Calico or Cilium, and is the standard way to achieve microsegmentation in Kubernetes.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.