Kubernetes and Cloud Native Associate (KCNA)Kubernetes FundamentalsHard

A cluster operator is configuring a new Kubernetes cluster and wants to ensure that all internal communication between Pods is encrypted by default. Which networking component or feature would be primarily responsible for enforcing such a policy?

  1. AService Mesh
  2. BCoreDNS
  3. Ckube-proxy
  4. DIngress Controller
Show answer & explanation

Correct answer: A. Service Mesh

A Service Mesh, such as Istio or Linkerd, provides advanced networking capabilities including traffic encryption (mTLS), observability, and traffic management for inter-service communication within the cluster. This is the primary tool for enforcing encryption between Pods by default.

Why the other options are wrong

  • B. CoreDNS provides DNS resolution for services within the cluster, not encryption.
  • C. kube-proxy handles network proxying for Services and load balancing, but does not enforce encryption.
  • D. An Ingress Controller manages external access to services within the cluster, typically handling TLS termination for incoming traffic, not internal Pod-to-Pod encryption.

Service Mesh

An infrastructure layer for handling service-to-service communication, providing features like traffic management, security (e.g., mTLS), and observability.

  • Manages inter-service communication.
  • Offers traffic encryption (mTLS).
  • Adds observability and policy enforcement.

Memory trick: Mesh your services for security!

More Kubernetes Fundamentals questions