CCSP Cloud Application Security Practice Question
A cloud application uses a service mesh for inter-service communication. The security team wants to enforce mutual TLS (mTLS) between all services and ensure that service identities are verified. What is the most effective way to achieve this?
⚠ Common exam trap
ISC2 often tests the misconception that network-layer encryption (IPsec or VPN) is sufficient for service-to-service authentication, but the key requirement here is per-service identity verification at the application layer, which only a service mesh's mTLS with certificate management can provide.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the service mesh's built-in mTLS and certificate management
The service mesh's built-in mTLS and certificate management is the most effective approach because it provides automatic, transparent mutual TLS encryption and identity verification at the application layer, using X.509 certificates issued by the mesh's certificate authority (e.g., Istio's Citadel or Linkerd's identity controller). This ensures that every inter-service communication is authenticated and encrypted without requiring changes to application code, and it integrates directly with the service mesh's identity model (e.g., Kubernetes service accounts).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set up Kerberos authentication between services
Why it's wrong here
Kerberos authenticates principals to services but does not provide the per-workload cryptographic identity and certificate-based mTLS that a service mesh issues and rotates. It is tempting because it is a mature authentication protocol, and would be correct where the requirement is authenticating users or hosts within an existing Kerberos realm rather than encrypting service-to-service traffic.
- ✗
Configure a VPN between all service subnets
Why it's wrong here
A VPN encrypts traffic between subnets but authenticates hosts or gateways, not individual service workloads, so it cannot verify per-service cryptographic identity or issue workload certificates. It is tempting because VPNs do secure inter-subnet traffic, and would suit connecting separate networks or cloud regions rather than service-to-service mTLS inside a mesh.
- ✗
Implement IPsec in the network layer
Why it's wrong here
IPsec operates at the network layer, encrypting packets between endpoints identified by IP addresses, so it cannot bind cryptographic identity to individual service accounts or rotate per-workload certificates. It is tempting because IPsec does provide strong transport encryption, and would be correct for securing site-to-site or host-to-host tunnels, not mesh service identities.
- ✓
Use the service mesh's built-in mTLS and certificate management
Why this is correct
The service mesh's built-in mTLS issues and rotates workload certificates, authenticating service identities via SPIFFE-style identities without application code changes. This satisfies the stem's requirement to enforce mutual TLS and verify service identities across all inter-service communication automatically.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.