CompTIA SecurityX (CAS-005)Security EngineeringHard

A global organization is implementing a Zero Trust architecture. As part of this initiative, all internal microservices communications must be mutually authenticated and encrypted, regardless of their network location. This requires an enforcement mechanism that operates at the application layer and can manage certificates for thousands of ephemeral service instances. Which technology BEST addresses this requirement?

  1. AService Mesh with mTLS
  2. BHost-based Firewall
  3. CIPsec VPN
  4. DNetwork Access Control (NAC)
Show answer & explanation

Correct answer: A. Service Mesh with mTLS

A service mesh, combined with mutual TLS (mTLS), provides the ideal solution. It intercepts all traffic between microservices, automatically handles certificate provisioning and rotation, and enforces mTLS for mutual authentication and encryption at the application layer, crucial for a Zero Trust environment with ephemeral services.

Why the other options are wrong

  • B. Host-based firewalls manage network traffic at the host level but do not inherently provide mutual authentication, certificate management, or encryption for application-layer communications between services.
  • C. IPsec VPNs operate at the network layer and are typically used for site-to-site or client-to-site connectivity, not fine-grained microservice-to-microservice authentication and encryption.
  • D. Network Access Control (NAC) primarily focuses on authenticating and authorizing devices connecting to the network, not on encrypting and mutually authenticating application-layer traffic between internal services.

Service Mesh with mTLS

A dedicated infrastructure layer that handles service-to-service communication, providing features like mutual TLS (mTLS) for mutual authentication and encryption between microservices in a Zero Trust environment.

  • Enables Zero Trust for microservices
  • Automates mTLS for authentication and encryption
  • Manages certificates for ephemeral service instances

Memory trick: Service Mesh with mTLS: Every microservice gets its own security bodyguard!

More Security Engineering questions