CompTIA Cloud+ (CV0-004)SecurityMedium

A cloud security engineer is implementing a new customer-facing application that processes sensitive personal identifiable information (PII). The application uses a microservices architecture deployed on Kubernetes. To ensure that communication between microservices is encrypted and authenticated, and to enforce fine-grained authorization policies, which solution should the engineer implement?

  1. AConfigure Network Access Control Lists (NACLs) for each microservice pod.
  2. BDeploy a service mesh to manage inter-service communication.
  3. CImplement a VPN connection between each microservice.
  4. DUtilize a Web Application Firewall (WAF) at the ingress controller.
Show answer & explanation

Correct answer: B. Deploy a service mesh to manage inter-service communication.

A service mesh (e.g., Istio, Linkerd) is specifically designed for microservices architectures to handle inter-service communication. It provides features like automatic mTLS (encryption and authentication), traffic management, and policy enforcement (fine-grained authorization) without requiring changes to application code.

Why the other options are wrong

  • A. NACLs operate at the subnet level and are stateless, making them unsuitable for fine-grained, dynamic, and identity-based authorization between individual microservice pods.
  • C. Implementing VPNs between microservices is impractical and inefficient for dynamic, highly interconnected microservices within a Kubernetes cluster.
  • D. A WAF protects the application at the edge from common web exploits but does not provide encryption, authentication, or fine-grained authorization for internal, inter-service communication.

Service Mesh

A dedicated infrastructure layer for handling service-to-service communication in microservices architectures, enabling secure and observable interactions.

  • Provides mTLS for encryption/authentication.
  • Enforces fine-grained authorization policies.
  • Abstracts networking concerns from application code.

Memory trick: Service mesh makes microservices talk securely.

More Security questions