Kubernetes and Cloud Native Associate (KCNA)Cloud Native ArchitectureHard

A cloud-native application processes sensitive user data across multiple microservices. The security team requires that all communication between these services is encrypted and mutually authenticated, even within the private network, to prevent unauthorized access and data tampering. Which feature of a service mesh addresses this requirement most effectively?

  1. ATraffic Routing
  2. BCircuit Breaking
  3. CMutual TLS (mTLS)
  4. DRate Limiting
Show answer & explanation

Correct answer: C. Mutual TLS (mTLS)

Mutual TLS (mTLS) in a service mesh ensures that both client and server services authenticate each other using certificates and encrypts all traffic between them, fulfilling the requirement for encrypted and mutually authenticated communication.

Why the other options are wrong

  • A. Traffic Routing controls how requests are directed between services, not their encryption or authentication.
  • B. Circuit Breaking prevents a failing service from being overwhelmed by requests, focusing on resilience, not security.
  • D. Rate Limiting controls the number of requests a service receives, focusing on stability, not encryption or authentication.

Service Mesh Mutual TLS (mTLS)

A security feature within a service mesh that establishes encrypted and mutually authenticated communication channels between services. Both the client and server services verify each other's identities using TLS certificates.

  • Encrypts all inter-service traffic.
  • Requires both client and server to authenticate.
  • Enhances security posture within the service mesh.
  • Often managed transparently by the mesh's sidecar proxies.

Memory trick: Mesh security: mTLS for mutual trust, policies for control.

More Cloud Native Architecture questions