Courseiva

CSSLP Practice Question: Secure Software Deployment Operations And Management

A security analyst notices anomalous outbound traffic from a containerized microservice that was recently deployed. Which Kubernetes feature should be used to restrict this traffic to only known authorized endpoints?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Apply a NetworkPolicy object that defines specific egress rules for the application namespace.

Kubernetes Network Policies are the standard resource for enforcing micro-segmentation and egress traffic control at the pod level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable the Kubernetes Audit Log and monitor for kubectl exec commands.

    Why it's wrong here

    Audit logs detect the activity but do not provide network-level isolation.

  • Configure PodSecurityPolicies to restrict the containers to non-root users.

    Why it's wrong here

    PodSecurityPolicies focus on runtime privilege, not network traffic egress.

  • Install a Service Mesh like Istio to enforce mTLS.

    Why it's wrong here

    mTLS secures the communication channel, but does not inherently restrict egress destinations unless combined with egress gateways.

  • Apply a NetworkPolicy object that defines specific egress rules for the application namespace.

    Why this is correct

    NetworkPolicies explicitly define which traffic flows are permitted, effectively mitigating unauthorized egress.

About these practice questions

This CSSLP question is part of Courseiva's 198-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official (ISC)² exam blueprint

This CSSLP practice question is part of Courseiva's free (ISC)² certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CSSLP exam.