CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A security architect is designing a new microservices-based application for a financial institution. The application will handle sensitive customer data and must maintain high availability and integrity, even in the face of partial system failures or malicious attacks. Which of the following design principles is MOST critical for ensuring the application's resilience and security in this scenario?

  1. ASynchronous inter-service communication
  2. BLoose coupling and bounded contexts
  3. CMonolithic architecture for core services
  4. DCentralized logging and monitoring
Show answer & explanation

Correct answer: B. Loose coupling and bounded contexts

Loose coupling and bounded contexts are fundamental to microservices architecture, promoting resilience by isolating failures and enhancing security by limiting the blast radius of a compromise. This allows for independent development, deployment, and scaling, which are crucial for maintaining high availability and integrity in a complex financial system.

Why the other options are wrong

  • A. Synchronous communication increases dependencies between services, making the system less resilient to individual service failures and potentially creating bottlenecks.
  • C. Monolithic architecture is antithetical to microservices and typically reduces resilience and increases the impact of failures, making it unsuitable for this scenario.
  • D. While important for security operations, centralized logging and monitoring do not directly contribute to the architectural resilience against partial failures or attacks.

Loose Coupling & Bounded Contexts

Loose coupling in software design means components are independent and have minimal dependencies on each other. Bounded contexts define explicit boundaries within a domain where a particular model is consistent, preventing unintended side effects.

  • Reduces interdependencies between services.
  • Limits the scope of data and functionality within a service.
  • Enhances system resilience by preventing cascading failures.
  • Improves security by isolating data and functionality.

Memory trick: Microservices thrive when they are like independent islands with clear shores.

More Security Architecture questions