Skip to content
CNPA
Platform Observability, Security, and Conformance
medium
Question 4 of 40

A platform team wants traffic between microservices inside a Kubernetes cluster to be encrypted in transit and services to authenticate each other's identity without hardcoding certificates. Which approach best satisfies both requirements?

AManually distributing TLS certificates as Kubernetes Secrets to each service team
BUsing a service mesh with mutual TLS that handles certificate issuance and rotation automatically
CEncrypting only external ingress traffic and trusting all internal pod-to-pod traffic implicitly
DApplying NetworkPolicy rules to block all traffic on unencrypted port 80

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion