KubeRusted
Spinning up your cluster…

ICA exam prep — Istio Certified Associate

Free ICA (Istio Certified Associate) practice: the 4 official domains, exam-style questions, a timed practice exam and more.

Play the ICA map → · Official ICA exam page

Installation, Upgrade & Configuration (20%)

istioctl or Helm, sidecar or ambient mode, customizing, canary and in-place upgrades

Traffic Management (35%)

Ingress/egress, routing, DestinationRules, traffic shifting, resilience, fault injection

Securing Workloads (25%)

Authorization, authentication (mTLS, JWT), TLS at the edge

Troubleshooting (20%)

Configuration, the mesh control plane and the mesh data plane

Practice questions

Which istioctl command checks a cluster before installing Istio?

Answer: istioctl x precheck. precheck looks for problems such as unsupported Kubernetes versions.

Which installation profile is intended for production sidecar meshes?

Answer: default. demo enables extra features and high tracing sampling for trying things out.

Which Helm charts install a sidecar-mode Istio control plane?

Answer: base; istiod. base installs CRDs and cluster resources; the gateway chart adds ingress gateways. ztunnel is for ambient.

Which additional components does ambient mode install?

Answer: ztunnel (DaemonSet); istio-cni. ambient uses node-level ztunnel and the CNI agent to redirect traffic.

How do you label a namespace for a specific control-plane revision in a canary upgrade?

Answer: istio.io/rev=<revision>. Remove the istio-injection label when using revision labels.

After moving a namespace to a new revision, what makes the workloads use the new proxies?

Answer: Restarting the workloads so new sidecars are injected. Existing sidecars stay at the old version until Pods are recreated.

Which IstioOperator / Helm setting turns on Envoy access logs mesh-wide?

Answer: meshConfig.accessLogFile: /dev/stdout. The Telemetry API can enable access logging more selectively.

How do you exclude one Pod from sidecar injection in an injected namespace?

Answer: Label the Pod sidecar.istio.io/inject: "false". The Pod label overrides the namespace setting.

What does istioctl verify-install check?

Answer: That the installed resources match the expected installation. Useful right after install or upgrade.

Which resource exposes a host on port 443 through the ingress gateway?

Answer: A Gateway with a server for that host and port. A VirtualService bound to the Gateway then routes the traffic.

How is a VirtualService attached to an ingress Gateway?

Answer: Listing the Gateway under spec.gateways. Without gateways, a VirtualService applies to mesh-internal traffic (the "mesh" gateway).

A VirtualService routes users with header end-user: jason to v2, everyone else to v1. Where must the jason rule be?

Answer: Before the default route. Routes are evaluated in order; the first match wins.

Which VirtualService match type matches a URI prefix?

Answer: uri: { prefix: /api }. exact and regex are the other StringMatch types.

How do you rewrite /v1/api to /api before forwarding?

Answer: A VirtualService http rule with rewrite.uri. rewrite also supports authority (Host header).

How do you mirror live traffic to v2 without affecting responses?

Answer: VirtualService mirror (with mirrorPercentage). Mirrored requests are fire-and-forget; responses are discarded.

Which DestinationRule setting changes the load-balancing algorithm?

Answer: trafficPolicy.loadBalancer.simple (e.g. LEAST_REQUEST). consistentHash enables sticky sessions by header or cookie.

How do you route to a subset that is defined by a label version: v2?

Answer: Define subset v2 with labels {version: v2} in a DestinationRule and reference it in the route. Routing to an undefined subset makes requests fail (503).

What does a VirtualService retry policy with attempts: 3, perTryTimeout: 2s mean?

Answer: Up to 3 retries, each attempt limited to 2 seconds. retryOn lists which failures trigger a retry.

Which setting caps concurrent HTTP/1.1 requests waiting for a connection to a service?

Answer: connectionPool.http.http1MaxPendingRequests. Requests beyond the limit fail fast (circuit breaking).

What does outlierDetection.baseEjectionTime control?

Answer: How long an ejected host stays out of the pool (growing with repeated ejections). interval sets how often hosts are analysed.

How do you return HTTP 503 for 10% of requests to test error handling?

Answer: fault.abort with httpStatus: 503 and percentage.value: 10. abort injects errors; delay injects latency.

Which resource lets in-mesh workloads reach a database running on a VM outside Kubernetes?

Answer: ServiceEntry (with WorkloadEntry for the VM). The VM then appears in the mesh registry.

How do you force mesh egress to an external host through a dedicated egress gateway?

Answer: A ServiceEntry plus a Gateway and VirtualService routing the host via the egress gateway. Centralizing egress lets you monitor and control outbound traffic.

What does the Sidecar resource configure?

Answer: Which services a proxy can reach (egress hosts) and its listeners, reducing config size. Limiting egress hosts cuts memory use in large meshes.

How do you shift all traffic from v1 to v2 after a successful canary?

Answer: Set the VirtualService weights to 0 for v1 and 100 for v2. Weights decide the split, so 0/100 sends everything to v2; only then remove the v1 Deployment and subset.

Which ambient-mode component is required for L7 features such as HTTP routing?

Answer: A waypoint proxy. ztunnel only handles L4: mTLS, telemetry and L4 authorization.

During migration to mTLS, which PeerAuthentication mode accepts both plaintext and mTLS?

Answer: PERMISSIVE. Switch to STRICT once all clients have sidecars.

A namespace-level PeerAuthentication says PERMISSIVE and the mesh-wide one says STRICT. What applies in that namespace?

Answer: PERMISSIVE — the more specific policy wins. Workload-level beats namespace-level, which beats mesh-wide.

Which AuthorizationPolicy source field matches a calling workload identity?

Answer: principals (e.g. cluster.local/ns/shop/sa/frontend). principals come from mTLS certificates; requestPrincipals from JWTs.

Allow only GET requests from the frontend ServiceAccount to the backend. Which policy?

Answer: ALLOW with from.source.principals = frontend SA and to.operation.methods = [GET]. Once any ALLOW policy applies, unmatched requests are denied.

Which AuthorizationPolicy action delegates the decision to an external authorizer?

Answer: CUSTOM. The provider is configured in meshConfig.extensionProviders.

Where does an AuthorizationPolicy in the root namespace apply?

Answer: Mesh-wide (to all workloads). The root namespace is istio-system by default.

What does RequestAuthentication jwtRules need to validate a token?

Answer: The issuer and a JWKS (jwksUri or jwks). Only the public keys are needed to verify signatures.

Which DestinationRule tls.mode makes the sidecar originate Istio mTLS to the destination?

Answer: ISTIO_MUTUAL. With auto mTLS this is usually configured automatically.

A Gateway server uses tls.mode: MUTUAL. What must clients present?

Answer: A client certificate trusted by the configured CA. The credential Secret must include ca.crt for client verification.

Which Gateway TLS mode passes encrypted traffic through to the backend using SNI routing?

Answer: PASSTHROUGH. The gateway does not terminate TLS; the backend does.

How does Istio issue workload certificates?

Answer: istiod acts as a CA and signs certificates for each workload’s SPIFFE identity. Certificates are short-lived and rotated automatically.

Which identity format does Istio use for workloads?

Answer: SPIFFE IDs such as spiffe://cluster.local/ns/<ns>/sa/<sa>. Identities are tied to ServiceAccounts.

Requests return 503 with response flag NR right after adding a subset route. What is likely missing?

Answer: A DestinationRule defining that subset. Routes to unknown subsets cannot be resolved by Envoy.

Requests are denied with RBAC: access denied. Which resource is responsible?

Answer: An AuthorizationPolicy. Istio’s authorization filter returns that message (HTTP 403).

Which command shows the Envoy clusters a sidecar knows about?

Answer: istioctl proxy-config cluster <pod>. Other subcommands: listener, route, endpoint, secret.

Which command shows whether mTLS certificates are loaded in a proxy?

Answer: istioctl proxy-config secret <pod>. It lists the workload certificate and root CA with validity.

Where do you read the sidecar proxy’s logs?

Answer: kubectl logs <pod> -c istio-proxy. istiod logs show control-plane problems; istio-proxy shows data-plane problems.

How do you raise the Envoy log level of one proxy to debug?

Answer: istioctl proxy-config log <pod> --level debug. It changes the level at runtime without restarting the Pod.

istioctl analyze reports IST0102 "namespace is not enabled for Istio injection". What is it telling you?

Answer: Pods in that namespace will not get sidecars. Label the namespace if it should be in the mesh.

A Pod in an injected namespace has only one container. Most likely?

Answer: It was created before injection was enabled, or injection is disabled for it. Check labels/annotations and restart the Pod.

Which response flag means the upstream connection was reset or failed?

Answer: UF (upstream connection failure). NR = no route; DC = downstream connection termination; RL = rate limited.

Which tool gives a graphical view of mesh traffic and configuration validation?

Answer: Kiali. Kiali uses Prometheus metrics and Istio config to draw the service graph.

You labelled namespace shop with istio-injection=enabled, but the running Pods still have no sidecar. Why?

Answer: Injection only happens at Pod creation — restart the workloads. The injection webhook mutates Pods when they are created; existing Pods are untouched.

In ambient mode, which component provides mTLS and L4 policy on each node?

Answer: ztunnel. ztunnel is the node-level L4 proxy; waypoints add L7 features only where you deploy them.

Which upgrade approach lets you move namespaces to the new control plane one at a time?

Answer: A canary (revision-based) upgrade with istio.io/rev labels. Two istiod revisions run side by side and each namespace opts in by revision label.

Send 90% of traffic to reviews v1 and 10% to v2. Which resources?

Answer: A DestinationRule defining subsets v1/v2 and a VirtualService with weights 90/10. Subsets are defined in the DestinationRule; weights live in the VirtualService route.

The mesh uses outboundTrafficPolicy REGISTRY_ONLY. How do you allow calls to api.stripe.com?

Answer: Create a ServiceEntry for api.stripe.com. REGISTRY_ONLY blocks hosts not in the mesh registry; a ServiceEntry adds it.

Temporarily eject an endpoint that returns five 5xx errors in a row. Which setting?

Answer: outlierDetection.consecutive5xxErrors in a DestinationRule. Outlier detection is passive health checking: unhealthy hosts are ejected from the load-balancing pool.

Test how the app behaves when ratings is slow — only for user "jason". How?

Answer: A VirtualService fault.delay on a route matching the end-user: jason header. Fault injection with a header match affects only the targeted test traffic.

Require mTLS for every workload in the mesh. What do you apply?

Answer: A PeerAuthentication with mtls.mode: STRICT in the root namespace (istio-system). PeerAuthentication controls workload-to-workload mTLS; in the root namespace it is mesh-wide.

A RequestAuthentication is in place, yet requests without any JWT still succeed. What is missing?

Answer: An AuthorizationPolicy requiring requestPrincipals. RequestAuthentication rejects invalid tokens but lets token-less requests through; authorization must demand a principal.

You apply an AuthorizationPolicy with action ALLOW and an empty spec otherwise to namespace prod. Effect?

Answer: All requests to workloads in prod are denied. An ALLOW policy with no matching rules allows nothing, so everything is denied.

A proxy shows STALE in istioctl proxy-status. What does it mean?

Answer: istiod pushed config the proxy has not acknowledged. SYNCED means the proxy acknowledged the latest push; STALE points at control-plane ↔ proxy problems.

Envoy access logs show response flag NR. What is wrong?

Answer: No route matched the request — check the VirtualService/Gateway hosts and matches. NR = no route configured; UH would be no healthy upstream, UO an overflow.