CompTIA Cloud+ (CV0-004)SecurityHard

A cloud security engineer is tasked with securing a new Kubernetes cluster deployed in a public cloud. The cluster hosts several microservices that communicate with each other, and the engineer needs to implement granular network policies to control traffic flow between these services. Additionally, they want to enforce security policies at the application layer (Layer 7) and gain better visibility into inter-service communication. Which architectural component would best address these requirements?

  1. AVirtual Private Network (VPN)
  2. BLoad Balancer
  3. CNetwork Security Groups (NSGs)
  4. DService Mesh
Show answer & explanation

Correct answer: D. Service Mesh

A service mesh (e.g., Istio, Linkerd) provides a dedicated infrastructure layer for handling service-to-service communication within a microservices architecture. It enables granular traffic control, policy enforcement (including Layer 7), observability, and security features like mTLS between services, directly addressing all the requirements for the Kubernetes cluster.

Why the other options are wrong

  • A. A VPN provides secure, encrypted tunnels for network traffic, typically between networks or to remote users, not for granular control or visibility of inter-service communication within a cluster.
  • B. A Load Balancer distributes incoming network traffic across multiple servers but does not provide granular security policies or Layer 7 control between services within the cluster.
  • C. NSGs operate at Layer 3/4 and are too coarse-grained for granular inter-service communication control within a Kubernetes cluster.

Service Mesh

A service mesh is a dedicated infrastructure layer that handles service-to-service communication in a microservices architecture, providing features like traffic management, security, and observability.

  • Manages communication between services, not end-users.
  • Enables granular control (Layer 7), policy enforcement, and mTLS.
  • Offers enhanced observability (metrics, logs, traces) for microservices.

Memory trick: Mesh protects microservices from within.

More Security questions