CompTIA Security+ (SY0-701)Security ArchitectureHard
A company migrates a monolithic application into dozens of independently deployed microservices running in containers. Security engineers want every service-to-service call to be mutually authenticated and encrypted without requiring each development team to write custom TLS code. Which architectural solution BEST meets this requirement?
- AA web application firewall in front of the cluster
- BA service mesh with sidecar proxies enforcing mTLS
- CA single shared TLS certificate installed on all containers
- DNetwork-level IPsec tunnels between cloud regions
Show answer & explanationAnswer & explanation
Correct answer: B. A service mesh with sidecar proxies enforcing mTLS
A service mesh injects sidecar proxies alongside each microservice to transparently handle mutual TLS, identity verification, and encrypted communication between services, removing the burden from individual development teams.
Why the other options are wrong
- A. A WAF protects against web application attacks at the edge, not internal service-to-service authentication.
- C. A single shared certificate does not provide mutual per-service identity and is a poor security practice.
- D. IPsec tunnels secure region-to-region traffic but don't provide per-service mutual authentication inside a cluster.
Service Mesh (mTLS)
An infrastructure layer that manages service-to-service communication in microservices architectures, typically using sidecar proxies to enforce mutual TLS and policy without changing application code.
- Sidecar proxies (e.g., Envoy) run alongside each service instance
- Provides mTLS, traffic policy, observability, and retries transparently
- Examples: Istio, Linkerd
Memory trick: 'A mesh of tiny bodyguards encrypts every handshake between services.'