CompTIA SecurityX (CAS-005)Security ArchitectureEasy

A development team is implementing a new API gateway for an internal application. The gateway needs to enforce authorization policies, handle rate limiting, and protect against common web vulnerabilities. Which architectural pattern would BEST integrate these security functions into the API gateway?

  1. AReverse Proxy
  2. BLoad Balancer
  3. CService Mesh
  4. DSidecar Proxy
Show answer & explanation

Correct answer: A. Reverse Proxy

A reverse proxy is an architectural pattern often used as an API gateway. It sits in front of backend services, intercepting all requests and allowing for centralized enforcement of policies like authorization, rate limiting, and WAF capabilities before requests reach the application.

Why the other options are wrong

  • B. A load balancer distributes traffic across multiple servers to ensure availability and performance, but it doesn't inherently provide the security policy enforcement described.
  • C. A service mesh is primarily for inter-service communication within a cluster, not typically for external API gateway functions at the edge.
  • D. A sidecar proxy is deployed alongside an application instance to handle concerns like logging, monitoring, and communication, but it's not the primary pattern for an API gateway's edge security functions.

Reverse Proxy

A server that sits in front of web servers and forwards client requests to those web servers. It can be used to handle various tasks such as load balancing, authentication, caching, and security enforcement.

  • Intercepts client requests before they reach the origin server.
  • Can perform security functions like WAF, authorization, rate limiting.
  • Improves performance by caching and load balancing.
  • Hides the identity and structure of backend servers.

Memory trick: The gatekeeper stands at the front, guarding the path.

More Security Architecture questions