Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityHard
A financial institution is deploying a highly sensitive application to a Kubernetes cluster. To meet stringent compliance requirements, they need to ensure that all network traffic between microservices within the cluster is encrypted and that access policies are enforced at the application layer (Layer 7), including mutual TLS (mTLS) for authentication. Which cloud-native security solution is best suited to fulfill these requirements?
- AKubernetes NetworkPolicies
- BService Mesh
- CIngress Controller with TLS
- DExternal Firewall
Show answer & explanationAnswer & explanation
Correct answer: B. Service Mesh
A Service Mesh (like Istio or Linkerd) provides robust features for encrypting inter-service communication (mTLS), enforcing Layer 7 policies, and offering advanced traffic management and observability, which are critical for sensitive applications and compliance.
Why the other options are wrong
- A. Kubernetes NetworkPolicies operate at Layer 3/4 and cannot enforce mTLS or Layer 7 policies.
- C. An Ingress Controller primarily handles incoming traffic from outside the cluster and typically terminates TLS at the edge, not for inter-service communication within the cluster.
- D. An External Firewall protects the cluster perimeter but does not govern or encrypt internal microservice communication.
Service Mesh for Security
A dedicated infrastructure layer that handles service-to-service communication, providing capabilities like traffic management, observability, and robust security features such as mutual TLS (mTLS) and fine-grained access control.
- Encrypts inter-service communication (mTLS).
- Enforces Layer 7 (application layer) policies.
- Provides centralized control over network security within the cluster.
Memory trick: Service Mesh secures every hop, from app to app.