CompTIA SecurityX (CAS-005)Security EngineeringMedium

A global enterprise is implementing a Zero Trust architecture across its highly distributed cloud environment. As part of this initiative, the security team needs to ensure that all service-to-service communication within the microservices ecosystem is mutually authenticated and encrypted, regardless of network location. Which technology is BEST suited to achieve this goal efficiently and at scale?

  1. ANetwork Access Control (NAC)
  2. BService Mesh with mTLS
  3. CCloud Access Security Broker (CASB)
  4. DVirtual Private Network (VPN)
Show answer & explanation

Correct answer: B. Service Mesh with mTLS

A service mesh, particularly one implementing mutual TLS (mTLS) between services, is ideal for Zero Trust in microservices. It automatically handles mutual authentication, encryption, and authorization for service-to-service communication at the application layer, without requiring changes to application code.

Why the other options are wrong

  • A. NAC controls access to a network based on device posture and user identity, primarily for endpoint access, not service-to-service communication within an application architecture.
  • C. CASBs focus on securing access to cloud services (SaaS, PaaS, IaaS) from users, not internal service-to-service communication within an application.
  • D. VPNs secure network connections between endpoints or networks, but typically operate at a lower layer and are not designed for fine-grained, automated service-to-service mTLS within a microservices ecosystem.

Service Mesh with mTLS

A dedicated infrastructure layer for handling service-to-service communication in a microservices architecture, often implementing mutual TLS (mTLS) for authentication and encryption.

  • Provides traffic management, observability, and security features
  • Automates mTLS for service authentication and encryption
  • Enables Zero Trust principles for inter-service communication

Memory trick: Mesh with mTLS: Microservices Mutually Trust.

More Security Engineering questions