Certified Cloud Security Professional (CCSP)Cloud Application SecurityHard

A financial institution is migrating a legacy monolithic application to a microservices architecture in the cloud. Each microservice will expose APIs, and sensitive data will flow between them. The security architect needs to ensure secure communication and proper authorization between these services without relying solely on network-level controls. Which security technology is best suited for this requirement?

  1. AServer-side encryption for all data at rest within each microservice database.
  2. BDistributed Denial of Service (DDoS) mitigation services.
  3. CIdentity and Access Management (IAM) policies with OAuth 2.0 and OpenID Connect.
  4. DVirtual Private Network (VPN) tunnels between each microservice.
Show answer & explanation

Correct answer: C. Identity and Access Management (IAM) policies with OAuth 2.0 and OpenID Connect.

IAM policies, combined with standards like OAuth 2.0 for authorization and OpenID Connect for authentication, provide a robust, granular, and scalable mechanism for managing secure communication and authorization between microservices, which often interact over internal APIs.

Why the other options are wrong

  • A. Server-side encryption for data at rest is crucial for data protection, but it doesn't directly address the secure communication and authorization *between* microservices.
  • B. DDoS mitigation protects against external volumetric attacks, but it does not address internal authorization or secure communication between trusted microservices.
  • D. VPNs are for network-level secure tunnels, which are too coarse-grained and complex to manage for inter-microservice communication in a dynamic cloud environment.

Microservices API Security

Securing communication and access between individual microservices, often relying on API-centric authentication and authorization mechanisms rather than just network controls.

  • Requires granular access control.
  • Often uses token-based authentication (e.g., JWT).
  • IAM plays a central role in managing permissions.

Memory trick: Microservices need 'IAM to Talk', not just network walls.

More Cloud Application Security questions