easyMultiple Choice
CAS-004 Uses Kubernetes to orchestrate containers Practice Question
An organization uses Kubernetes to orchestrate containers. Which practice enhances the security of pod-to-pod communication?
⚠ Common exam trap
A common misconception is that ClusterIP services inherently secure pod-to-pod communication, but ClusterIP only provides service discovery and load balancing, not traffic filtering or segmentation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement network policies that restrict ingress and egress traffic based on labels.
Network policies in Kubernetes act as a firewall for pods, allowing you to define ingress and egress rules based on labels, namespaces, or IP blocks. By default, all pod-to-pod traffic is allowed; implementing network policies restricts this traffic to only what is explicitly permitted, thereby enhancing security by enforcing the principle of least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement network policies that restrict ingress and egress traffic based on labels.
Why this is correct
Kubernetes network policies act as pod-level firewalls, selecting pods by label and permitting only declared ingress and egress flows. This segments pod-to-pod traffic, blocking lateral movement between compromised containers that would otherwise communicate freely on the flat cluster network.
- ✗
Expose all pods via NodePort services.
Why it's wrong here
NodePort publishes each pod's service on every node's IP, widening the reachable surface rather than restricting pod-to-pod flows. It is tempting as a quick way to expose workloads, but that is external service publishing; internal segmentation requires a network policy selecting pods by label.
- ✗
Use ClusterIP services for all internal traffic.
Why it's wrong here
ClusterIP only assigns a stable virtual IP for service load-balancing; it enforces no allow or deny decision between pods, so traffic still flows freely. It tempts because it keeps services internal, but internal reachability differs from authorisation, which NetworkPolicy provides.
- ✗
Rely on the default Kubernetes network configuration.
Why it's wrong here
Kubernetes' default networking is flat and non-isolating: every pod can reach every other pod unless a NetworkPolicy selects it. Relying on defaults is tempting because clusters work immediately without extra manifests, but that permissiveness is precisely the gap pod-to-pod security must close.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.