CompTIA SecurityX (CAS-005)Security EngineeringHard

A large enterprise is migrating its legacy monolithic applications to a microservices architecture running on Kubernetes. The security team needs to implement a solution that ensures all inter-service communication within the cluster is mutually authenticated and encrypted, without requiring developers to embed cryptographic logic into each microservice. This solution should also provide fine-grained authorization policies based on service identity. Which component of a service mesh would BEST address these requirements?

  1. AAPI Gateway
  2. BIngress Controller
  3. CSidecar Proxy
  4. DContainer Network Interface (CNI)
Show answer & explanation

Correct answer: C. Sidecar Proxy

A sidecar proxy, a core component of a service mesh, intercepts all inbound and outbound network traffic for a microservice. It can transparently handle mutual TLS (mTLS) for encryption and authentication, and enforce fine-grained authorization policies based on service identity, without developers needing to modify application code.

Why the other options are wrong

  • A. An API Gateway manages API traffic from external clients to microservices, typically handling authentication, rate limiting, and routing, but does not usually manage inter-service mTLS or authorization within the cluster itself.
  • B. An Ingress Controller manages external access to services within the cluster, not inter-service communication or mutual authentication within the cluster.
  • D. CNI provides network connectivity for pods in a Kubernetes cluster; it's a low-level networking component, not responsible for mTLS or fine-grained service authorization policies.

Sidecar Proxy (Service Mesh)

A lightweight proxy deployed alongside each application container (microservice) in a Kubernetes pod. It intercepts all network traffic to and from the microservice, offloading network and security functions from the application logic.

  • Enables transparent mutual TLS (mTLS) between services.
  • Enforces traffic policies and authorization.
  • Removes security and network concerns from application code.

Memory trick: Sidecar Secures Inter-Service Connections.

More Security Engineering questions