Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A security engineer is hardening a Kubernetes cluster that runs multi-tenant workloads. The team wants to ensure that a compromised pod cannot reach the cloud provider's instance metadata service to steal node credentials. Which control BEST addresses this?

⚠ Common exam trap

The trap here is assuming that workload hardening controls such as PodSecurity or mTLS also restrict network paths to the metadata service, when only explicit egress filtering addresses that link-local access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enforce a NetworkPolicy that denies egress to the link-local address 169.254.169.254 from all pods.

Blocking egress to 169.254.169.254 with a NetworkPolicy directly prevents pods from reaching the instance metadata service, which is the specific vector for stealing node credentials. PodSecurity, credential rotation, and service mesh mTLS address different risks and do not stop a pod from querying the metadata endpoint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rotate node IAM credentials every 24 hours using the cloud provider's rotation service.

    Why it's wrong here

    Rotation reduces the window of misuse but does not prevent a compromised pod from retrieving current valid credentials. An attacker with immediate access can exfiltrate and use the credentials before rotation occurs, so this is a mitigation of impact, not prevention of access.

  • ✗

    Enable PodSecurity admission with the restricted profile on all namespaces.

    Why it's wrong here

    PodSecurity admission restricts privilege escalation, hostPath mounts, and capabilities, but it does not control network egress. A pod running under the restricted profile can still open a TCP connection to the metadata endpoint and retrieve node credentials, so this does not address the stated risk.

  • ✗

    Use a service mesh with mutual TLS between all workloads in the cluster.

    Why it's wrong here

    mTLS secures service-to-service traffic but does not block a pod from directly contacting the link-local metadata IP. The metadata endpoint is outside the mesh's identity model, so a compromised pod can still fetch node credentials. This control addresses inter-service authentication, not metadata access.

  • ✓

    Enforce a NetworkPolicy that denies egress to the link-local address 169.254.169.254 from all pods.

    Why this is correct

    The instance metadata service is reachable at 169.254.169.254 from the node network namespace, and pods on the node can often reach it. A default-deny egress NetworkPolicy targeting that link-local address blocks pods from retrieving node IAM credentials, directly mitigating the credential theft scenario.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.