CompTIA Cloud+ (CV0-004)SecurityHard
A cloud security engineer needs to implement secure communication between microservices within a Kubernetes cluster. The solution must ensure that all inter-service traffic is encrypted and authenticated, providing mutual TLS (mTLS) without requiring developers to manually implement cryptographic libraries in each service. Which technology would best facilitate this?
- AService Mesh
- BLoad Balancer
- CContainer Network Interface (CNI)
- DAPI Gateway
Show answer & explanationAnswer & explanation
Correct answer: A. Service Mesh
A service mesh (e.g., Istio, Linkerd, Consul Connect) provides capabilities like automatic mTLS, traffic encryption, and authentication for inter-service communication without requiring code changes within the microservices themselves. It typically injects sidecar proxies that handle the cryptographic operations, abstracting this complexity from developers.
Why the other options are wrong
- B. A Load Balancer distributes traffic but doesn't inherently provide mTLS or encryption for internal service-to-service communication.
- C. A CNI provides network connectivity for containers but does not offer mTLS, encryption, or advanced security policies for service-to-service communication.
- D. An API Gateway manages external client requests to microservices, not typically inter-service communication within the cluster.
Service Mesh (mTLS)
A service mesh provides a transparent layer for microservices to enable features like mutual TLS (mTLS) for encrypted and authenticated inter-service communication, without requiring application code changes.
- Automates mTLS and encryption for service-to-service traffic.
- Decouples security concerns from application logic.
- Enhances observability and policy enforcement for microservices.
Memory trick: Mesh weaves mTLS into every service call.