CompTIA Cloud+ (CV0-004)SecurityMedium

A company is deploying a new web application in a public cloud. The application uses microservices architecture and needs fine-grained traffic control between individual services, as well as features like mutual TLS (mTLS) for strong authentication and encryption between service-to-service communications. A cloud security engineer recommends a solution that can manage and observe this inter-service communication. Which of the following technologies is best suited for this purpose?

  1. AService Mesh
  2. BVirtual Private Cloud (VPC)
  3. CNetwork Load Balancer (NLB)
  4. DContent Delivery Network (CDN)
Show answer & explanation

Correct answer: A. Service Mesh

A service mesh, such as Istio or Linkerd, is specifically designed to manage and secure service-to-service communication in microservices architectures, offering features like mTLS, traffic management, and observability.

Why the other options are wrong

  • B. A VPC provides network isolation for resources but does not offer fine-grained control or security features for inter-service communication within the VPC.
  • C. A Network Load Balancer operates at Layer 4 and distributes traffic, but it doesn't provide the advanced security features like mTLS or fine-grained traffic control between microservices.
  • D. A CDN is used to cache and deliver content quickly to end-users globally, not for securing or managing internal service-to-service communication.

Service Mesh

A dedicated infrastructure layer for handling service-to-service communication in microservices architectures. It provides features like traffic management, security (mTLS), and observability.

  • Simplifies inter-service communication management.
  • Enables mutual TLS for strong authentication.
  • Offers traffic routing, resiliency, and monitoring.

Memory trick: Service Meshes Make Microservices Marvelously Monitored.

More Security questions