Courseiva

CCSP Cloud Application Security Practice Question

A cloud application uses a service mesh for inter-service communication. The security team wants to enforce mutual TLS (mTLS) between all services and ensure that service identities are verified. What is the most effective way to achieve this?

⚠ Common exam trap

ISC2 often tests the misconception that network-layer encryption (IPsec or VPN) is sufficient for service-to-service authentication, but the key requirement here is per-service identity verification at the application layer, which only a service mesh's mTLS with certificate management can provide.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the service mesh's built-in mTLS and certificate management

The service mesh's built-in mTLS and certificate management is the most effective approach because it provides automatic, transparent mutual TLS encryption and identity verification at the application layer, using X.509 certificates issued by the mesh's certificate authority (e.g., Istio's Citadel or Linkerd's identity controller). This ensures that every inter-service communication is authenticated and encrypted without requiring changes to application code, and it integrates directly with the service mesh's identity model (e.g., Kubernetes service accounts).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set up Kerberos authentication between services

    Why it's wrong here

    Kerberos authenticates principals to services but does not provide the per-workload cryptographic identity and certificate-based mTLS that a service mesh issues and rotates. It is tempting because it is a mature authentication protocol, and would be correct where the requirement is authenticating users or hosts within an existing Kerberos realm rather than encrypting service-to-service traffic.

  • ✗

    Configure a VPN between all service subnets

    Why it's wrong here

    A VPN encrypts traffic between subnets but authenticates hosts or gateways, not individual service workloads, so it cannot verify per-service cryptographic identity or issue workload certificates. It is tempting because VPNs do secure inter-subnet traffic, and would suit connecting separate networks or cloud regions rather than service-to-service mTLS inside a mesh.

  • ✗

    Implement IPsec in the network layer

    Why it's wrong here

    IPsec operates at the network layer, encrypting packets between endpoints identified by IP addresses, so it cannot bind cryptographic identity to individual service accounts or rotate per-workload certificates. It is tempting because IPsec does provide strong transport encryption, and would be correct for securing site-to-site or host-to-host tunnels, not mesh service identities.

  • ✓

    Use the service mesh's built-in mTLS and certificate management

    Why this is correct

    The service mesh's built-in mTLS issues and rotates workload certificates, authenticating service identities via SPIFFE-style identities without application code changes. This satisfies the stem's requirement to enforce mutual TLS and verify service identities across all inter-service communication automatically.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.