Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityHard
A company is developing a new microservices application using Azure Kubernetes Service (AKS). The application consists of several microservices that communicate with each other. The security team mandates a zero-trust network policy, meaning that no microservice should implicitly trust another, and all inter-service communication must be authenticated and authorized. Which security pattern should be implemented to enforce this zero-trust communication within the AKS cluster?
- AService Mesh (e.g., Istio or Linkerd)
- BAzure Private Link
- CKubernetes Network Policies
- DNetwork Security Groups (NSG)
Show answer & explanationAnswer & explanation
Correct answer: A. Service Mesh (e.g., Istio or Linkerd)
A Service Mesh (like Istio or Linkerd) is specifically designed to handle inter-service communication, including traffic management, observability, and security. For zero-trust, a service mesh provides features like mutual TLS (mTLS) for authenticating and encrypting all service-to-service communication, and fine-grained authorization policies based on service identity, enforcing the 'never trust, always verify' principle.
Why the other options are wrong
- B. Azure Private Link provides private connectivity to Azure PaaS services (e.g., Storage, SQL Database) from a VNet. It is not designed to secure inter-service communication within an AKS cluster.
- C. Kubernetes Network Policies enforce Layer 3/4 packet filtering between pods based on labels. While useful for segmentation, they do not provide identity-based authentication (mTLS) or fine-grained authorization policies at the application layer necessary for a full zero-trust model.
- D. Network Security Groups (NSGs) operate at Layer 4 (IP/port) and provide basic network filtering between subnets or VMs. They are not granular enough for per-service authentication and authorization within a Kubernetes cluster for zero-trust.
Service Mesh for Zero-Trust
A dedicated infrastructure layer that handles inter-service communication within a microservices architecture, enabling features like mutual TLS for zero-trust security.
- Provides mutual TLS (mTLS) for authenticating and encrypting all service-to-service traffic.
- Enforces fine-grained authorization policies based on service identity.
- Offers traffic management, observability, and resiliency features.
Memory trick: Service Mesh: Every microservice gets its own security guard and ID check.