Courseiva

Google PCA Design for security and compliance Practice Question

A financial services company runs a containerized trading platform on Google Kubernetes Engine (GKE). Compliance requires that all inter-pod traffic be encrypted without modifying application code, and that the encryption keys be managed by the company rather than Google. The security team wants to enforce this at the infrastructure level. Which approach should they take?

⚠ Common exam trap

The trap here is assuming that GKE NetworkPolicy or VPC Service Controls provide encryption, when they only control traffic flow or API perimeters.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Istio with mutual TLS (mTLS) and a custom certificate authority managed by the company.

Istio's mutual TLS encrypts all service-to-service traffic within the mesh without requiring application changes. By integrating Istio's certificate authority with a company-managed CA, the organization retains control over encryption keys. NetworkPolicy and VPC Service Controls do not encrypt traffic, and Application-layer Secrets Encryption only protects secrets at rest, not network data in transit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure Istio with mutual TLS (mTLS) and a custom certificate authority managed by the company.

    Why this is correct

    Istio with mTLS encrypts all service-to-service traffic transparently without application changes. When you integrate Istio's certificate authority with a company-managed CA, the keys and certificates are controlled by the organization, satisfying the requirement that keys be company-managed. This approach enforces encryption at the infrastructure layer for all inter-pod communication.

  • ✗

    Enable Application-layer Secrets Encryption with a Cloud KMS key on the GKE cluster.

    Why it's wrong here

    Application-layer Secrets Encryption protects Kubernetes Secrets stored in etcd, not inter-pod network traffic. It uses a Cloud KMS key to encrypt secret data at rest, but it does not provide encryption for pod-to-pod communication. This option addresses a different security concern and would leave inter-pod traffic unencrypted, failing the compliance requirement.

  • ✗

    Use VPC Service Controls to create a service perimeter around the GKE cluster.

    Why it's wrong here

    VPC Service Controls define security perimeters around Google Cloud services to mitigate data exfiltration, but they do not encrypt traffic between pods. They operate at the API level for managed services and do not provide in-cluster encryption. This option would not encrypt inter-pod communication and thus fails to meet the compliance requirement.

  • ✗

    Enable GKE network policy enforcement and create NetworkPolicy resources to allow only encrypted traffic.

    Why it's wrong here

    GKE NetworkPolicy controls which pods can communicate, but it does not encrypt traffic. NetworkPolicy operates at layers 3 and 4 to allow or deny connections based on labels and ports; it cannot enforce encryption. Enabling it would restrict traffic flow but leave data in plaintext, so it does not meet the encryption requirement.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.