Kubernetes and Cloud Native Associate (KCNA)Cloud Native ArchitectureHard
A financial institution is deploying a highly sensitive payment processing microservice. They need to ensure that all traffic between this service and other internal services is encrypted, authenticated, and authorized, without requiring developers to embed complex security logic into each service's code. Which cloud native component can transparently enforce these security policies for inter-service communication?
- AIdentity and Access Management (IAM)
- BService Mesh
- CContainer Network Interface (CNI)
- DSecrets Management System
Show answer & explanationAnswer & explanation
Correct answer: B. Service Mesh
A service mesh, through its sidecar proxies, can transparently inject and enforce security policies like mutual TLS (mTLS) for encryption and authentication, and fine-grained authorization rules for inter-service communication, without requiring changes to application code.
Why the other options are wrong
- A. IAM manages user and service identities and permissions, but doesn't directly enforce encryption/authentication for inter-service traffic.
- C. CNI provides network connectivity for containers, not security policies for application-level communication.
- D. A secrets management system stores sensitive data, but doesn't actively enforce communication security policies.
Service Mesh Security
The ability of a service mesh to provide transparent encryption, authentication, and authorization for inter-service communication, often using mutual TLS (mTLS) and fine-grained access policies.
- Enforces mTLS for all service traffic.
- Provides granular authorization policies.
- Offloads security logic from application code.
- Enhances overall microservices security posture.
Memory trick: The Service Mesh is the security guard for all internal service conversations.