Certified Cloud Security Professional (CCSP)Cloud Application SecurityHard
A financial institution is migrating its legacy monolithic application to a cloud-native microservices architecture. The new architecture requires secure communication between microservices, each running in its own container. The security team wants to ensure that communication is encrypted and mutually authenticated, and that policies can be uniformly applied across all services. What is the most effective technology to achieve this within the microservices environment?
- AIndividual VPN tunnels between each microservice.
- BA service mesh with mutual TLS (mTLS) enabled.
- CA centralized Web Application Firewall (WAF) protecting the entire cluster.
- DAPI keys and secrets managed in a distributed key-value store.
Show answer & explanationAnswer & explanation
Correct answer: B. A service mesh with mutual TLS (mTLS) enabled.
A service mesh with mTLS provides automated, strong identity and mutual authentication for each microservice, encrypting all inter-service communication. It also allows for uniform policy enforcement across all services, which is ideal for securing a complex microservices environment without manual configuration of individual connections.
Why the other options are wrong
- A. Individual VPN tunnels would be overly complex, difficult to manage, and introduce significant overhead in a dynamic microservices environment.
- C. A WAF protects external traffic but provides limited visibility or control over internal, inter-service communication within a cluster.
- D. API keys and distributed key-value stores manage secrets but do not inherently provide mutual authentication, encryption of the communication channel, or policy enforcement across services.
Service Mesh with mTLS
A service mesh provides network capabilities for microservices, and mutual TLS (mTLS) within it ensures that all service-to-service communication is encrypted and mutually authenticated using certificates.
- Automated identity and certificate management.
- Encrypts all traffic between services.
- Enables uniform policy enforcement across services.
Memory trick: Mesh with mTLS makes microservices talk securely and politely.