CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A security architect is designing a microservices-based application where individual services need to communicate securely and be resilient to failures. Each service should enforce fine-grained authorization policies based on runtime attributes, and communication between services must be mutually authenticated and encrypted. The solution should also provide traffic management capabilities like load balancing and circuit breaking. Which architectural pattern best addresses these requirements?
- AAPI Gateway
- BService Mesh
- CMonolithic Architecture
- DEvent-Driven Architecture
Show answer & explanationAnswer & explanation
Correct answer: B. Service Mesh
A service mesh provides a dedicated infrastructure layer for handling service-to-service communication, offering capabilities like mutual TLS for authentication/encryption, fine-grained access control, traffic management, and resiliency features without requiring changes to the application code.
Why the other options are wrong
- A. An API Gateway primarily handles external client requests and routing, not internal service-to-service communication with fine-grained controls and resiliency.
- C. Monolithic Architecture is an application structure that contradicts the microservices-based requirement and does not inherently provide these communication benefits.
- D. Event-Driven Architecture is a communication paradigm, not an infrastructure layer for securing and managing service-to-service calls.
Service Mesh
A dedicated infrastructure layer that handles service-to-service communication within a microservices architecture, providing features like traffic management, security, and observability.
- Decouples communication logic from application code.
- Often implemented with a 'sidecar proxy' pattern.
- Provides security features like mTLS, authorization, and traffic encryption.
Memory trick: Mesh your services for secure, resilient, and observable connections.