CompTIA SecurityX (CAS-005)Security ArchitectureHard

A security architect is designing a new cloud-native application that will handle sensitive financial transactions. To ensure secure, authenticated, and authorized communication between microservices within the application's service mesh, without relying on traditional network perimeter controls, which mechanism should be implemented?

  1. ABasic HTTP authentication
  2. BIP whitelisting
  3. CMutual TLS (mTLS)
  4. DShared secret API keys
Show answer & explanation

Correct answer: C. Mutual TLS (mTLS)

Mutual TLS (mTLS) provides strong, cryptographically verified two-way authentication between microservices, ensuring that both the client and server are verified before any communication occurs. This is ideal for a Zero Trust approach within a service mesh, as it does not rely on network location.

Why the other options are wrong

  • A. Basic HTTP authentication is weak and not suitable for securing sensitive microservices communication.
  • B. IP whitelisting relies on network location and is less effective in dynamic cloud-native environments and service meshes where IP addresses can change.
  • D. Shared secret API keys can be vulnerable to compromise and do not provide the same level of cryptographic identity verification as mTLS.

Mutual TLS (mTLS)

An extension of TLS where both the client and the server present digital certificates to each other for mutual authentication, establishing a cryptographically secured and trusted communication channel.

  • Provides two-way authentication (client and server).
  • Ensures data confidentiality and integrity.
  • Foundational for Zero Trust in service meshes.

Memory trick: mTLS: 'Mutual Trust, Layered Security' for your services.

More Security Architecture questions