Which of the following are benefits of using Consul for service discovery? (select 3)
The latest changes and updates from the administration for this exam.
Latest Update: Jun 09 2026
All questions are working fine.
Which of the following are benefits of using Consul for service discovery? (select 3)
Select all that apply
True or False? Using the / character, Consul organizes the data in a directory structure, similar to a file system.
While all of the TLS encryption settings are recommended, only some satisfy the security/threat model. When you set verify_server_hostname to true, what is true about the TLS certificate for this to work properly? (select three)
Select all that apply
You have a Consul cluster running production workloads in your environment. However, you've discovered that the cluster was initially deployed without gossip encryption configured, which means that traffic is being sent in cleartext. The security team has requested this to be updated ASAP. However, you can't take an outage on the Consul service right now, knowing the server nodes will stop communicating once you start editing the configuration files one by one.
How can you enable gossip encryption on the existing cluster without affecting the services it is currently providing the business?
What ports does Consul use as the default for the incoming DNS listener, where clients can send DNS queries for service discovery? (select two)
Select all that apply
You have successfully configured a service and a related sidecar proxy in Consul. You have started the web service and verified that it is running but the traffic is not being passed through the local proxy to reach the destination service. What could be a reason for this? (select two)

Select all that apply
You've logged into the Consul UI and want to modify the policy that is used by a token assigned to an application. However, you see this screen when clicking the ACL tab. What must you provide in order to access the ACL configuration page?

Your security team has established company policies that require encryption keys to be rotated at least once a year for all applicable systems. Consul has been identified as an affected system, and the encryption key for gossip must be rotated across the entire environment. However, you have multiple Consul clusters, each consisting of five Consul nodes and hundreds of services registered with Consul, each of which has the gossip key explicitly written to the configuration file.
What built-in Consul feature allows you to distribute a new encryption key to all the servers and nodes and remove the old one?
There are two methods for creating and distributing client certificates for Consul. What are the two? (select two)
Select all that apply
Based on the Consul agent configuration below, what parameter will determine which interface Consul will use for internal cluster communications?
