Courseiva
Security →hardMultiple Select

CV0-004 Security Practice Question

A cloud security team is implementing a zero-trust security model for a microservices application deployed on Azure Kubernetes Service (AKS). The team needs to ensure that all service-to-service communication is authenticated and encrypted, and that access policies are enforced based on service identity rather than network location. Which TWO components should the team implement to achieve these goals? (Choose two.)

⚠ Common exam trap

The trap here is assuming that network-layer controls like firewalls or NSGs can provide identity-based authentication and encryption for microservices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Open Service Mesh (OSM) with mutual TLS (mTLS) enabled

A zero-trust model for microservices requires strong service identities and encrypted, authenticated communication. Microsoft Entra ID workload identities provide the identity plane, allowing services to authenticate using Microsoft Entra ID tokens. Open Service Mesh with mTLS provides the data plane encryption and enforces access policies based on those identities. Together, they ensure that service-to-service communication is both authenticated and encrypted, independent of network location.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Open Service Mesh (OSM) with mutual TLS (mTLS) enabled

    Why this is correct

    Open Service Mesh (OSM) is a lightweight service mesh that provides mTLS for service-to-service communication, encrypting traffic and authenticating service identities. It enforces access policies based on service accounts, aligning with zero-trust principles. OSM integrates natively with AKS and can leverage Microsoft Entra ID workload identities for certificate management, making it essential for encrypted and authenticated communication.

  • ✓

    Microsoft Entra ID (Azure AD) workload identities

    Why this is correct

    Microsoft Entra ID workload identities allow Kubernetes pods to authenticate to Azure services and to each other using Microsoft Entra ID tokens. This provides a strong identity foundation for zero-trust, enabling service-to-service authentication based on identity rather than network location. It integrates with AKS and supports OIDC federation, making it a key component for authenticating microservices.

  • ✗

    Network Security Groups (NSGs) with service tags

    Why it's wrong here

    NSGs filter traffic based on IP addresses, ports, and service tags. They operate at the network layer and cannot authenticate service identities or encrypt traffic. While NSGs are useful for segmentation, they do not provide the identity-based, encrypted communication required for a zero-trust model. They are a network control, not an identity or encryption control.

  • ✗

    Azure Bastion for secure remote access to AKS nodes

    Why it's wrong here

    Azure Bastion provides secure RDP/SSH access to virtual machines without exposing public IPs. It is used for administrative access, not for service-to-service communication within a microservices application. It does not authenticate or encrypt inter-service traffic, so it is irrelevant to the zero-trust requirement for microservices.

  • ✗

    Azure Firewall with network rules based on IP addresses

    Why it's wrong here

    Azure Firewall operates at the network layer and enforces rules based on IP addresses, ports, and protocols. It does not provide service identity-based authentication or encryption. In a zero-trust model, network location is not trusted, so IP-based rules alone are insufficient. This component does not meet the requirement for identity-based access and encrypted communication.

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.