CompTIA Cloud+ (CV0-004)SecurityMedium
A company is deploying a new web application in a public cloud. The application uses microservices architecture and needs fine-grained traffic control between individual services, as well as features like mutual TLS (mTLS) for strong authentication and encryption between service-to-service communications. A cloud security engineer recommends a solution that can manage and observe this inter-service communication. Which of the following technologies is best suited for this purpose?
- AService Mesh
- BVirtual Private Cloud (VPC)
- CNetwork Load Balancer (NLB)
- DContent Delivery Network (CDN)
Show answer & explanationAnswer & explanation
Correct answer: A. Service Mesh
A service mesh, such as Istio or Linkerd, is specifically designed to manage and secure service-to-service communication in microservices architectures, offering features like mTLS, traffic management, and observability.
Why the other options are wrong
- B. A VPC provides network isolation for resources but does not offer fine-grained control or security features for inter-service communication within the VPC.
- C. A Network Load Balancer operates at Layer 4 and distributes traffic, but it doesn't provide the advanced security features like mTLS or fine-grained traffic control between microservices.
- D. A CDN is used to cache and deliver content quickly to end-users globally, not for securing or managing internal service-to-service communication.
Service Mesh
A dedicated infrastructure layer for handling service-to-service communication in microservices architectures. It provides features like traffic management, security (mTLS), and observability.
- Simplifies inter-service communication management.
- Enables mutual TLS for strong authentication.
- Offers traffic routing, resiliency, and monitoring.
Memory trick: Service Meshes Make Microservices Marvelously Monitored.