CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A security architect is designing a new cloud-native application that will process highly sensitive financial transaction data. The application will be deployed across multiple regions globally. To ensure data confidentiality and integrity during transit between microservices within the application and external APIs, which cryptographic control should the architect prioritize for implementation?

  1. AMutual TLS (mTLS) for all inter-service and external API communications.
  2. BHomomorphic encryption for all sensitive data processing.
  3. CIPsec tunnels between all microservice instances.
  4. DClient-side encryption for all data before transmission.
Show answer & explanation

Correct answer: A. Mutual TLS (mTLS) for all inter-service and external API communications.

Mutual TLS (mTLS) provides strong authentication and encryption for communications between services, ensuring both parties are verified and the data in transit is protected. This is crucial for highly sensitive financial data in a distributed cloud environment.

Why the other options are wrong

  • B. Homomorphic encryption allows computation on encrypted data but is computationally intensive and primarily addresses data confidentiality during processing, not specifically in-transit security between services.
  • C. IPsec tunnels are typically used for network-layer security between networks or hosts, which is less granular and flexible than mTLS for securing individual microservice communications within a cloud-native application.
  • D. Client-side encryption protects data before it leaves the client but doesn't inherently secure inter-service communication or API calls within the cloud environment.

Mutual TLS (mTLS)

Mutual TLS is a method for two communicating parties to authenticate each other using X.509 certificates as part of the TLS handshake. It ensures both the client and server verify each other's identity before establishing a secure communication channel.

  • Provides mutual authentication, unlike standard TLS which only authenticates the server.
  • Uses client certificates in addition to server certificates.
  • Enhances security for API communication and microservices.
  • Encrypts data in transit.

Memory trick: Mutual Trust Makes Transactions Transparently Secure.

More Security Architecture questions