Kubernetes and Cloud Native Associate (KCNA)Cloud Native ArchitectureHard

A cloud-native application processes sensitive user data across multiple microservices. To meet compliance requirements and enhance security, the development team needs to ensure that all service-to-service communication within the cluster is encrypted and authenticated at the transport layer, without relying on application-level encryption. Which service mesh feature should they enable?

  1. AMutual TLS (mTLS)
  2. BTraffic Shifting
  3. CDistributed Tracing
  4. DRate Limiting
Show answer & explanation

Correct answer: A. Mutual TLS (mTLS)

Mutual TLS (mTLS) in a service mesh ensures that both the client and server services authenticate each other and encrypt all communication between them at the transport layer. This meets the requirement for encrypted and authenticated service-to-service communication without application code changes.

Why the other options are wrong

  • B. Traffic Shifting is for routing traffic between different versions of services, not for encryption or authentication.
  • C. Distributed Tracing helps visualize request flows across microservices for observability, not for securing communication.
  • D. Rate Limiting controls the number of requests a service can receive but does not provide encryption or authentication.

Mutual TLS (mTLS) in Service Mesh

A security feature in a service mesh that establishes encrypted and mutually authenticated connections between services, where both client and server verify each other's identity using TLS certificates.

  • Provides strong identity for services.
  • Encrypts all service-to-service traffic.
  • Enforces authentication at the transport layer.
  • Transparent to application code via sidecar proxies.

Memory trick: mTLS makes services mighty trustworthy.

More Cloud Native Architecture questions