CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A security architect is designing a new cloud-native application that will process sensitive customer data. The application will be deployed across multiple regions globally. The architect needs to ensure that data in transit between microservices within the same cloud region is encrypted and authenticated without significant performance overhead. Which of the following architectural patterns would BEST address this requirement?
- AImplementing a site-to-site VPN between each microservice.
- BDeploying individual reverse proxies for each microservice.
- CEnforcing HTTPS at the application load balancer level only.
- DUtilizing a service mesh with mutual TLS (mTLS) enabled.
Show answer & explanationAnswer & explanation
Correct answer: D. Utilizing a service mesh with mutual TLS (mTLS) enabled.
A service mesh with mutual TLS (mTLS) provides transparent, encrypted, and authenticated communication between microservices within a cluster, addressing both security and performance concerns efficiently. It automates certificate management and encryption, reducing operational overhead.
Why the other options are wrong
- A. Site-to-site VPNs are typically used for network-level encryption between different networks or data centers, not for granular microservice communication within the same region.
- B. Individual reverse proxies would add significant complexity and configuration overhead for each microservice and might not inherently provide mTLS for inter-service communication without additional setup.
- C. Enforcing HTTPS at the load balancer protects external traffic, but does not inherently secure traffic between microservices once inside the network boundary.
Service Mesh with mTLS
A service mesh is a dedicated infrastructure layer for handling service-to-service communication. When combined with mutual TLS (mTLS), it provides encrypted and authenticated communication between microservices, enhancing security and observability.
- Automates encryption and authentication for inter-service communication.
- Manages certificates and key rotation transparently.
- Provides granular control over traffic, policies, and observability.
- Reduces security burden on individual microservice developers.
Memory trick: Mesh your services with mutual trust for secure talk.