Skip to content

Service Mesh Questions

Practice questions for Service Mesh topic in Cilium Certified Associate. 32 questions covering this domain.

32 questions8 easy16 medium8 hard
Q1
medium

A backend application behind Cilium Gateway API needs the client address for HTTP requests. Which statement is correct?

Q2
medium

A platform team wants traffic splitting and header modification without relying on controller-specific annotations. Which Kubernetes API better fits t...

Q3
medium

Which prerequisite set is required for Cilium Gateway API support?

Q4
easy

Which component does Cilium service mesh use for application-layer protocols such as HTTP, Kafka, gRPC, and DNS?

Q5
hard

A security team applies CiliumNetworkPolicy to external traffic entering through Gateway API, but requests are still blocked unexpectedly. Which polic...

Q6
hard

A team enables TLS passthrough for Gateway API and then notices that the backend sees Envoy or node IPs instead of the real client IP. Why?

Q7
medium

When is Cilium Gateway API host network mode most appropriate?

Q8
easy

What does a service mesh primarily do for distributed applications according to the Cilium docs?

Q9
medium

A team migrates from a legacy Ingress controller to Cilium Gateway API. They need to redirect all HTTP traffic on port 80 to HTTPS on port 443. Which ...

Q10
hard

A platform engineer enables WireGuard transparent encryption on a Cilium cluster. They then attempt to also use IPsec transparent encryption on the sa...

Q11
hard

A security team audits a Cilium deployment and finds that pod-to-pod traffic on the same node is not encrypted even though WireGuard transparent encry...

Q12
medium

A cluster administrator wants to configure Cilium Ingress to share a single LoadBalancer IP across multiple Ingress resources rather than provisioning...

Q13
easy

An operator wants to deploy Cilium's Ingress controller to expose a backend service via HTTP. The cluster runs in a cloud environment that provides Lo...

Q14
medium

A platform team deploys Cilium service mesh and wants to enforce mutual authentication (mTLS) between specific services so that both sides verify each...

Q15
easy

Which two transparent encryption protocols does Cilium support for encrypting pod-to-pod traffic at the network layer without requiring changes to app...

Q16
medium

A DevOps team wants to use Cilium service mesh without deploying any sidecar proxies alongside their application pods, keeping resource overhead minim...

Q17
medium

A team wants a Gateway listener on port 443 in host network mode. What extra capability must be granted to Envoy?

Q18
easy

Which component validates Gateway API resources and marks them as Accepted before Envoy is configured?

Q19
medium

What happens when Cilium Gateway API host network mode is enabled?

Q20
hard

Gateway resources are not being programmed and the operator logs say Required GatewayAPI resources are not found. What is the most likely fix?

Sign in to see all 32 questions

Create a free account to browse all questions — completely free during our launch phase.