CompTIA Cloud+ (CV0-004)SecurityMedium
A cloud security engineer is implementing a new customer-facing application that processes sensitive personal identifiable information (PII). The application uses a microservices architecture deployed on Kubernetes. To ensure that communication between microservices is encrypted and authenticated, and to enforce fine-grained authorization policies, which solution should the engineer implement?
- AConfigure Network Access Control Lists (NACLs) for each microservice pod.
- BDeploy a service mesh to manage inter-service communication.
- CImplement a VPN connection between each microservice.
- DUtilize a Web Application Firewall (WAF) at the ingress controller.
Show answer & explanationAnswer & explanation
Correct answer: B. Deploy a service mesh to manage inter-service communication.
A service mesh (e.g., Istio, Linkerd) is specifically designed for microservices architectures to handle inter-service communication. It provides features like automatic mTLS (encryption and authentication), traffic management, and policy enforcement (fine-grained authorization) without requiring changes to application code.
Why the other options are wrong
- A. NACLs operate at the subnet level and are stateless, making them unsuitable for fine-grained, dynamic, and identity-based authorization between individual microservice pods.
- C. Implementing VPNs between microservices is impractical and inefficient for dynamic, highly interconnected microservices within a Kubernetes cluster.
- D. A WAF protects the application at the edge from common web exploits but does not provide encryption, authentication, or fine-grained authorization for internal, inter-service communication.
Service Mesh
A dedicated infrastructure layer for handling service-to-service communication in microservices architectures, enabling secure and observable interactions.
- Provides mTLS for encryption/authentication.
- Enforces fine-grained authorization policies.
- Abstracts networking concerns from application code.
Memory trick: Service mesh makes microservices talk securely.