CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A security architect is designing a new microservices-based application. The application will consist of numerous independent services communicating over a network. The architect needs to ensure that each service can cryptographically verify the identity of the other services it communicates with, and that all communication between them is encrypted, without relying on a central certificate authority for every service-to-service interaction. Which security mechanism is BEST suited for this requirement?

  1. AIPsec VPN tunnels between each service instance.
  2. BA service mesh with mutual TLS (mTLS).
  3. CA centralized API Gateway with client certificate authentication.
  4. DApplication-layer encryption for all data payloads.
Show answer & explanation

Correct answer: B. A service mesh with mutual TLS (mTLS).

A service mesh with mutual TLS provides automatic encryption and identity verification for service-to-service communication within a microservices architecture, simplifying management and enhancing security. It handles certificate issuance and rotation transparently.

Why the other options are wrong

  • A. IPsec VPNs are complex to manage at a per-service level in a dynamic microservices environment and don't inherently provide service identity verification at the application layer.
  • C. A centralized API Gateway only secures communication to the gateway, not between the internal microservices themselves, and requires manual client certificate management.
  • D. Application-layer encryption is good for data confidentiality but doesn't handle service identity verification or key management for inter-service communication automatically.

Service Mesh with mTLS

A service mesh is a dedicated infrastructure layer for handling service-to-service communication in a microservices environment. When combined with mutual TLS (mTLS), it provides transparent encryption and strong identity-based authentication for all inter-service traffic.

  • Automates encryption and authentication between microservices.
  • Provides identity verification for each service.
  • Simplifies network policy enforcement and observability.

Memory trick: Mesh with mTLS makes microservices safe and sound.

More Security Architecture questions