CompTIA SecurityX (CAS-005)Security EngineeringHard

A security team is implementing a Zero Trust architecture for a highly distributed cloud environment. A key requirement is to ensure that all network communication between workloads (e.g., containers, VMs) is mutually authenticated and authorized based on their identity, regardless of their network location. This should be transparent to developers and automatically enforced. Which technology or approach would BEST achieve this requirement?

  1. ATraditional network firewalls and VLAN segmentation.
  2. BSecurity Groups and Network Access Control Lists (NACLs).
  3. CService Mesh with mTLS and fine-grained authorization policies.
  4. DIPsec VPNs between each workload.
Show answer & explanation

Correct answer: C. Service Mesh with mTLS and fine-grained authorization policies.

A Service Mesh, particularly one that implements mutual TLS (mTLS) and supports fine-grained authorization policies (e.g., Istio, Linkerd), is purpose-built for Zero Trust in distributed cloud environments. It provides automatic, transparent encryption and mutual authentication for all inter-service communication (workload-to-workload) by injecting proxies (sidecars) alongside each workload. This allows authorization policies to be applied based on workload identity, fulfilling the requirement for identity-based, mutually authenticated communication regardless of network location, with minimal developer overhead.

Why the other options are wrong

  • A. Traditional firewalls and VLANs are network-centric and rely on IP addresses, not workload identity, and are difficult to manage at scale in a highly dynamic, distributed environment.
  • B. Security Groups and NACLs are infrastructure-level network controls, similar to firewalls, that rely on IP addresses and ports, not workload identity, and are not granular enough for application-layer identity-based authorization.
  • D. IPsec VPNs would be overly complex and resource-intensive to establish and manage between every individual workload in a highly distributed microservices architecture, and don't inherently provide identity-based authorization at the application layer.

Service Mesh (mTLS)

A service mesh is a dedicated infrastructure layer for handling service-to-service communication. It typically provides features like traffic management, observability, and security features such as mutual TLS (mTLS) for identity-based encryption and authentication.

  • Enables transparent, identity-based mutual authentication (mTLS).
  • Encrypts all inter-service communication.
  • Provides fine-grained authorization policies based on workload identity.
  • Decouples networking and security from application code, transparent to developers.

Memory trick: Service Mesh Makes Zero Trust Seamless

More Security Engineering questions