CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A security architect is evaluating a new cloud-native application that processes sensitive financial transactions. The application uses microservices communicating over HTTP/REST APIs. To enforce a consistent security policy, centralize authentication/authorization, and provide observability across all microservices, which architectural component should the architect recommend implementing?

  1. ADirect service-to-service communication with individual security libraries.
  2. BA dedicated Web Application Firewall (WAF) for each microservice.
  3. CA centralized API Gateway.
  4. DAn intrusion detection system (IDS) at the network perimeter.
Show answer & explanation

Correct answer: C. A centralized API Gateway.

A centralized API Gateway acts as a single entry point for all microservice requests. It can enforce security policies (authentication, authorization), handle rate limiting, transform requests, and provide centralized logging and monitoring, which is ideal for consistent security and observability in a microservices architecture.

Why the other options are wrong

  • A. Relying on individual security libraries in each microservice leads to inconsistent implementations, increased development effort, and dispersed observability, making policy enforcement difficult.
  • B. Deploying a WAF for each microservice would be overly complex, expensive, and difficult to manage for consistent policy enforcement across many services.
  • D. An IDS at the network perimeter monitors external threats but does not enforce internal microservice policies, centralize authentication, or provide granular observability within the application.

API Gateway

An API Gateway is a server that acts as an API front-end, taking requests from clients, routing them to the appropriate microservice, and often performing functions like authentication, authorization, rate limiting, and data transformation.

  • Single entry point for client requests to microservices.
  • Centralizes security policies (authN/authZ).
  • Provides observability (logging, metrics, tracing).
  • Reduces complexity for clients and individual microservices.

Memory trick: Gateway guards the city, routes traffic, and checks IDs.

More Security Architecture questions