CompTIA SecurityX (CAS-005)Security EngineeringHard
A large enterprise is migrating its legacy monolithic applications to a microservices architecture running on Kubernetes. The security team needs to implement a solution that ensures all inter-service communication within the cluster is mutually authenticated and encrypted, without requiring developers to embed cryptographic logic into each microservice. This solution should also provide fine-grained authorization policies based on service identity. Which component of a service mesh would BEST address these requirements?
- AAPI Gateway
- BIngress Controller
- CSidecar Proxy
- DContainer Network Interface (CNI)
Show answer & explanationAnswer & explanation
Correct answer: C. Sidecar Proxy
A sidecar proxy, a core component of a service mesh, intercepts all inbound and outbound network traffic for a microservice. It can transparently handle mutual TLS (mTLS) for encryption and authentication, and enforce fine-grained authorization policies based on service identity, without developers needing to modify application code.
Why the other options are wrong
- A. An API Gateway manages API traffic from external clients to microservices, typically handling authentication, rate limiting, and routing, but does not usually manage inter-service mTLS or authorization within the cluster itself.
- B. An Ingress Controller manages external access to services within the cluster, not inter-service communication or mutual authentication within the cluster.
- D. CNI provides network connectivity for pods in a Kubernetes cluster; it's a low-level networking component, not responsible for mTLS or fine-grained service authorization policies.
Sidecar Proxy (Service Mesh)
A lightweight proxy deployed alongside each application container (microservice) in a Kubernetes pod. It intercepts all network traffic to and from the microservice, offloading network and security functions from the application logic.
- Enables transparent mutual TLS (mTLS) between services.
- Enforces traffic policies and authorization.
- Removes security and network concerns from application code.
Memory trick: Sidecar Secures Inter-Service Connections.