CompTIA SecurityX (CAS-005)Security EngineeringMedium

A global enterprise is implementing a Zero Trust architecture across its highly distributed cloud environment. A key component of this strategy is to ensure that all service-to-service communication is mutually authenticated and encrypted, regardless of network location. The security team decides to deploy a solution that injects a transparent proxy alongside each application instance, handling all network traffic and enforcing security policies. This approach is commonly known as a:

  1. ALoad Balancer
  2. BContent Delivery Network (CDN)
  3. CReverse Proxy
  4. DService Mesh
Show answer & explanation

Correct answer: D. Service Mesh

A service mesh, typically implemented with sidecar proxies, provides capabilities like mutual TLS (mTLS) for service-to-service authentication and encryption, traffic management, and policy enforcement, which are fundamental to a Zero Trust architecture in a distributed environment.

Why the other options are wrong

  • A. A load balancer distributes incoming network traffic across multiple servers, but doesn't inherently provide mutual authentication or encryption for service-to-service communication.
  • B. A CDN primarily caches content closer to users to improve performance and availability, not for securing internal service-to-service communication.
  • C. A reverse proxy sits in front of web servers, forwarding client requests to them, and is not designed for comprehensive service-to-service security in a distributed system.

Service Mesh (mTLS)

A dedicated infrastructure layer that handles service-to-service communication, providing capabilities like mutual TLS (mTLS) for authentication and encryption, traffic management, and policy enforcement.

  • Uses sidecar proxies for transparent traffic interception
  • Enables mutual TLS (mTLS) for strong identity-based security
  • Crucial for Zero Trust in microservices architectures

Memory trick: Service Mesh Secures Services with Mutual Trust.

More Security Engineering questions