CompTIA Security+ (SY0-701)Security ArchitectureMedium

An organization exposes several backend microservices to external partners through a single entry point that enforces authentication, throttles excessive requests, and routes calls to the correct internal service. Which component is being described?

  1. AA jump server
  2. BAn API gateway
  3. CA network intrusion prevention system
  4. DA reverse proxy load balancer
Show answer & explanation

Correct answer: B. An API gateway

An API gateway is the standard architectural component in microservices environments that centralizes authentication, rate limiting, and request routing for backend services exposed to external consumers.

Why the other options are wrong

  • A. A jump server is used for administrative access to internal systems, not API traffic management.
  • C. An IPS inspects traffic for attack signatures; it doesn't route or authenticate API calls.
  • D. A reverse proxy load balancer distributes traffic but typically doesn't provide the full auth/throttling/routing feature set described.

API Gateway

A managed entry point for microservices that handles authentication, rate limiting, request routing, and monitoring for API traffic.

  • Centralizes cross-cutting concerns (auth, logging, throttling) so individual services don't duplicate them
  • Common in microservices architectures to hide internal service topology
  • Can enforce API keys, OAuth tokens, and quota limits

Memory trick: 'One gate, many rooms — the API gateway guards them all.'

More Security Architecture questions