CompTIA SecurityX (CAS-005)Security EngineeringHard

A security architect is implementing a Zero Trust architecture across a highly distributed cloud environment. The goal is to ensure that all service-to-service communication within the microservices ecosystem is mutually authenticated and encrypted, regardless of network location. The architect wants to achieve this without burdening developers with manual certificate management or complex network configurations. Which approach would BEST integrate into a service mesh to achieve this?

  1. ACentralized Certificate Authority (CA) for all services
  2. BAPI Gateway with OAuth 2.0
  3. CIPsec VPN tunnels between services
  4. DMutual Transport Layer Security (mTLS)
Show answer & explanation

Correct answer: D. Mutual Transport Layer Security (mTLS)

Within a service mesh, Mutual Transport Layer Security (mTLS) is the primary mechanism for achieving mutual authentication and encryption for service-to-service communication. The service mesh automatically injects sidecar proxies that handle certificate issuance, rotation, and mTLS handshakes, abstracting this complexity from developers while enforcing Zero Trust principles. While a CA is involved, the service mesh automates its use, and IPsec is too heavy for microservice communication.

Why the other options are wrong

  • A. A centralized CA is necessary for mTLS, but the 'without burdening developers with manual certificate management' part points to an automated solution like a service mesh with mTLS integration, not just the CA itself.
  • B. An API Gateway with OAuth 2.0 handles client-to-service authentication and authorization, but not necessarily service-to-service mutual authentication and encryption within the mesh.
  • C. IPsec VPNs are typically used for network-level encryption between networks or hosts, not granular, automated service-to-service encryption within a microservices mesh.

Service Mesh (mTLS)

A service mesh uses sidecar proxies to manage service-to-service communication, often implementing mutual TLS (mTLS) to provide automated mutual authentication and encryption.

  • Automates mTLS for all inter-service traffic.
  • Enforces Zero Trust principles by verifying every connection.
  • Abstracts network and security concerns from application developers.

Memory trick: Service mesh's mTLS makes every service handshake secure, no questions asked.

More Security Engineering questions