CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security architect is designing a new cloud-native application that will process highly sensitive personal identifiable information (PII). The application uses microservices, and each microservice needs to securely communicate with other microservices without relying on a centralized certificate authority or pre-shared keys for every connection. Which of the following advanced cryptographic techniques would BEST address this requirement?

  1. AHomomorphic Encryption
  2. BFormat-Preserving Encryption (FPE)
  3. CQuantum Key Distribution (QKD)
  4. DMutual Transport Layer Security (mTLS)
Show answer & explanation

Correct answer: D. Mutual Transport Layer Security (mTLS)

Mutual Transport Layer Security (mTLS) provides two-way authentication, ensuring that both the client and server verify each other's identities using certificates. This is ideal for secure microservice communication within a Zero Trust architecture, eliminating the need for centralized CAs or pre-shared keys for every individual service.

Why the other options are wrong

  • A. Homomorphic encryption allows computations on encrypted data but does not primarily address secure communication between services.
  • B. FPE encrypts data while retaining its original format, useful for database fields, but not for mutual authentication between services.
  • C. QKD is a method for securely exchanging cryptographic keys using quantum mechanics, not directly for securing microservice communication authentication.

Mutual TLS (mTLS)

Mutual TLS is a method for two-way authentication where both the client and server present certificates to each other to verify their identities.

  • Provides strong authentication for both ends of a connection.
  • Commonly used in Zero Trust architectures and microservices.
  • Relies on public key infrastructure (PKI) for certificate issuance.

Memory trick: Microservices mutually trust, like a secure handshake.

More Security Engineering questions