CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A security architect is designing a new cloud-native application that will handle sensitive customer data. The application needs to ensure that data in transit between microservices within the same Virtual Private Cloud (VPC) is always encrypted and authenticated to prevent eavesdropping and tampering, even if the VPC's underlying network fabric is compromised. Which security mechanism is BEST suited to address this requirement?
- ASecurity Groups to filter inbound and outbound traffic.
- BVPN tunnels between different subnets within the VPC.
- CNetwork Access Control Lists (NACLs) to restrict traffic flow.
- DMutual TLS (mTLS) between microservices.
Show answer & explanationAnswer & explanation
Correct answer: D. Mutual TLS (mTLS) between microservices.
Mutual TLS (mTLS) provides strong encryption and authentication at the application layer, ensuring that even within a trusted network boundary like a VPC, each microservice verifies the identity of the other and encrypts communication. This protects against threats like compromised network fabric or rogue internal services.
Why the other options are wrong
- A. Security Groups operate at the instance level and filter traffic based on IP addresses and ports, but do not provide application-layer encryption or mutual authentication.
- B. VPN tunnels are typically used for connecting VPCs to on-premises networks or between different VPCs, not for securing inter-service communication within the same VPC at the application layer.
- C. NACLs operate at the subnet level and primarily control traffic flow, not encryption or mutual authentication between specific services.
Mutual TLS (mTLS)
Mutual TLS (mTLS) is a security protocol that ensures both the client and server verify each other's identity using digital certificates during a TLS handshake, providing mutual authentication and encrypted communication.
- Both parties present and validate certificates.
- Provides strong authentication and encryption.
- Commonly used in microservices architectures and Zero Trust environments.
Memory trick: Microservices need to 'shake hands' with trust, not just 'knock on the door'.