CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A security architect is designing a new microservices-based application that will handle sensitive customer data. The architecture requires that each microservice can independently verify the identity and authorization of requests originating from other microservices, without relying on a central authentication service for every inter-service call. Which architectural pattern best addresses this requirement?

  1. AService Mesh with mTLS
  2. BCentralized API Gateway
  3. CContent Delivery Network (CDN)
  4. DStateless Load Balancer
Show answer & explanation

Correct answer: A. Service Mesh with mTLS

A service mesh with mutual TLS (mTLS) provides a robust solution for inter-service authentication and authorization in microservices architectures. It enables each service to verify the identity of other services through cryptographic certificates, ensuring secure communication without constant reliance on a central authority for every transaction.

Why the other options are wrong

  • B. A centralized API Gateway handles external requests but typically doesn't manage granular inter-service authentication within the mesh.
  • C. A Content Delivery Network (CDN) primarily caches and delivers static content, which is unrelated to inter-service authentication.
  • D. A stateless load balancer distributes traffic but does not provide identity verification or secure communication between service instances.

Service Mesh with mTLS

A service mesh is a dedicated infrastructure layer that handles service-to-service communication, reliability, and security. When combined with mutual TLS (mTLS), it provides strong cryptographic identity and secure, authenticated communication between microservices.

  • Provides secure inter-service communication.
  • Enables strong identity verification using certificates.
  • Offloads security concerns from individual microservices.

Memory trick: Mesh and Mutually TLS protect the tiny services.

More Security Architecture questions