CAS-004 Security Engineering Practice Question
A security engineer is hardening a Kubernetes cluster that runs multi-tenant workloads. The requirement is to prevent a compromised pod from reading another tenant's secrets and from making unauthorized network connections to other namespaces. Which of the following combinations BEST addresses both concerns?
⚠ Common exam trap
The trap here is treating transport encryption or audit logging as if it prevents unauthorized access, when only authorization and segmentation controls actually block the actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply network policies that deny ingress and egress by default and mount secrets only into pods that explicitly require them with least-privilege service accounts
Default-deny network policies enforce network segmentation between namespaces, and least-privilege service accounts with scoped secret mounts enforce secret isolation at the API level. The other options harden adjacent layers such as control-plane access, admission, or transport encryption without preventing the two specific cross-tenant actions described.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable role-based access control (RBAC) for the API server and require TLS client certificates for all kubelet connections
Why it's wrong here
RBAC and kubelet TLS harden control-plane and node communications, which is valuable, but they do not restrict pod-to-pod network traffic or prevent a pod from reading secrets if its service account is over-privileged. The scenario specifically requires blocking cross-namespace network connections and secret reads, which these controls alone do not deliver.
- ✗
Deploy a service mesh with mutual TLS between all pods and rotate the cluster's certificate authority on a fixed schedule
Why it's wrong here
Mutual TLS encrypts and authenticates service-to-service traffic, but encryption alone does not stop an authenticated pod from connecting to a service in another namespace unless authorization policy is also configured. Rotating the CA addresses certificate hygiene, not secret isolation. Neither control prevents reading secrets through an over-privileged service account.
- ✗
Use pod security admission to enforce the restricted profile and enable audit logging on the API server for all secret access
Why it's wrong here
Pod security admission limits privileged container capabilities, and audit logging records secret access but does not prevent it. A compromised pod with a permissive service account could still read secrets, and without network policies it could still reach other namespaces. This combination detects and constrains some behavior but fails the preventive requirements.
- ✓
Apply network policies that deny ingress and egress by default and mount secrets only into pods that explicitly require them with least-privilege service accounts
Why this is correct
Default-deny network policies stop unauthorized cross-namespace connections, while scoping secret mounts and service account permissions to only the pods that need them prevents a compromised pod from reading other tenants' secrets. Together they address both the network and secret-access requirements directly.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.