CompTIA Cloud+ (CV0-004)SecurityHard

A cloud security engineer is tasked with securing a new Kubernetes cluster deployed in a public cloud. The requirement is to ensure that all communication between microservices within the cluster is encrypted and authenticated, and that network policies are enforced at the service level, independent of underlying network IP addresses. Which security mechanism is best suited for this purpose?

  1. AService Mesh
  2. BWeb Application Firewall (WAF)
  3. CVirtual Private Network (VPN)
  4. DNetwork Security Groups (NSG)
Show answer & explanation

Correct answer: A. Service Mesh

A service mesh (e.g., Istio, Linkerd) provides capabilities like mutual TLS (mTLS) for encrypted and authenticated communication between microservices, granular traffic management, and policy enforcement at the application/service layer, independent of network IP addresses. This aligns perfectly with the requirements for securing inter-microservice communication in Kubernetes.

Why the other options are wrong

  • B. A WAF protects web applications from common web exploits at the perimeter, not internal microservice communication within a cluster.
  • C. A VPN secures traffic between networks or clients and a network, but it's not designed for fine-grained, encrypted, and authenticated communication between individual microservices within a cluster.
  • D. NSGs operate at the network layer (Layer 3/4) based on IP addresses and ports, not at the service level with encryption/authentication for microservices.

Service Mesh

A dedicated infrastructure layer that handles service-to-service communication within a microservices architecture, providing capabilities like traffic management, security (mTLS), and observability.

  • Manages service-to-service communication
  • Provides mTLS for encryption and authentication
  • Enforces policies at the application/service layer

Memory trick: Service Mesh is the invisible security guardian for your microservice conversations.

More Security questions