CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A security architect is designing a new microservices-based application that will handle sensitive customer data. The architecture requires that each microservice can independently verify the identity and authorization of requests originating from other microservices, without relying on a central authentication service for every inter-service call. Which architectural pattern best addresses this requirement?
- AService Mesh with mTLS
- BCentralized API Gateway
- CContent Delivery Network (CDN)
- DStateless Load Balancer
Show answer & explanationAnswer & explanation
Correct answer: A. Service Mesh with mTLS
A service mesh with mutual TLS (mTLS) provides a robust solution for inter-service authentication and authorization in microservices architectures. It enables each service to verify the identity of other services through cryptographic certificates, ensuring secure communication without constant reliance on a central authority for every transaction.
Why the other options are wrong
- B. A centralized API Gateway handles external requests but typically doesn't manage granular inter-service authentication within the mesh.
- C. A Content Delivery Network (CDN) primarily caches and delivers static content, which is unrelated to inter-service authentication.
- D. A stateless load balancer distributes traffic but does not provide identity verification or secure communication between service instances.
Service Mesh with mTLS
A service mesh is a dedicated infrastructure layer that handles service-to-service communication, reliability, and security. When combined with mutual TLS (mTLS), it provides strong cryptographic identity and secure, authenticated communication between microservices.
- Provides secure inter-service communication.
- Enables strong identity verification using certificates.
- Offloads security concerns from individual microservices.
Memory trick: Mesh and Mutually TLS protect the tiny services.