Courseiva
Security Engineering →hardMultiple Choice

CAS-004 Security Engineering Practice Question

A security team is hardening a Kubernetes cluster that runs multi-tenant workloads. The team wants to prevent a compromised pod from reaching the cloud metadata service at 169.254.169.254 to steal node credentials, while still allowing pods to reach required external APIs. Which of the following should the team implement?

⚠ Common exam trap

The trap here is assuming that workload identity or RBAC hardening protects the metadata endpoint, when those controls govern different planes than the pod network path.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply a network policy that denies egress to the link-local metadata address while permitting approved external destinations.

Blocking pod egress to the link-local metadata address removes the direct path a compromised workload would use to obtain node credentials, and pairing it with an allow rule for required external APIs preserves functionality. Network policy operates below the application, so it constrains all processes in the selected pods without relying on application cooperation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Apply a network policy that denies egress to the link-local metadata address while permitting approved external destinations.

    Why this is correct

    Network policies can select pods and control egress by destination CIDR and port, so a rule denying 169.254.169.254 blocks the metadata path while a companion allow rule permits required external APIs. This is the least-disruptive control that directly removes the credential-theft vector without breaking legitimate traffic. It enforces the restriction at the pod network layer regardless of application behavior.

  • ✗

    Set the pod security context to run containers as a non-root user with a read-only root filesystem.

    Why it's wrong here

    Running as non-root and using a read-only filesystem reduce the impact of container compromise, but any process in the pod can still issue an HTTP request to the metadata address. These controls harden the container, not the network path to the metadata service. The credential theft would succeed because the endpoint remains reachable.

  • ✗

    Configure role-based access control so that pods run under a service account with no RBAC permissions.

    Why it's wrong here

    RBAC governs access to the Kubernetes API server, not the cloud instance metadata service. A pod with no API permissions can still query 169.254.169.254 and retrieve node-level credentials if the metadata service is reachable. Removing RBAC permissions therefore does not address the actual exfiltration path described in the scenario.

  • ✗

    Enable mutual TLS between all pods and require SPIFFE identities for service-to-service calls.

    Why it's wrong here

    Mutual TLS with workload identities secures service-to-service communication and helps prevent impersonation, but it does not stop a pod from making a direct HTTP request to the link-local metadata endpoint. The metadata service does not participate in the service mesh, so mTLS does not cover that path. The credential-theft vector would remain open.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.