CompTIA Cloud+ (CV0-004)DeploymentMedium

A development team is implementing a microservices architecture in the cloud. Each microservice needs to communicate with others, and the team wants to ensure that network traffic between services is secure and isolated, even within the same virtual network. Which network deployment strategy should the team implement?

  1. ADeploying all microservices in publicly accessible subnets.
  2. BUsing a single Virtual Private Cloud (VPC) without further segmentation.
  3. CPlacing all microservices in a single flat subnet.
  4. DUtilizing Network Security Groups (NSGs) or Security Groups to control traffic between subnets.
Show answer & explanation

Correct answer: D. Utilizing Network Security Groups (NSGs) or Security Groups to control traffic between subnets.

Network Security Groups (NSGs) or Security Groups provide granular control over inbound and outbound traffic for individual virtual machines, network interfaces, or subnets. This allows for isolation and secure communication between microservices, even if they reside within the same virtual network or VPC, by defining specific rules for allowed traffic.

Why the other options are wrong

  • A. Publicly accessible subnets increase the attack surface and reduce security, contrary to the requirement for secure and isolated communication.
  • B. A single VPC without further segmentation (like subnets and NSGs) would not provide the necessary isolation between microservices.
  • C. A single flat subnet offers no isolation or security segmentation between microservices.

Network Security Groups (NSGs)

Virtual firewalls that control inbound and outbound traffic to network interfaces (VMs) or subnets in a cloud environment.

  • Define rules for allowed/denied traffic.
  • Operate at Layer 4 (TCP/UDP) and Layer 3 (IP).
  • Provide granular network isolation and security.

Memory trick: Secure Network Zones Keep Everything Safe.

More Deployment questions