Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planEasy
A development team is implementing a new microservices-based application on Azure. They need to ensure that all communication between microservices is encrypted in transit and that each microservice can verify the identity of the other services it communicates with. Which Azure security feature should they prioritize for this requirement?
- AAzure Active Directory for service principal authentication
- BAzure Front Door with WAF policies
- CMutual TLS (mTLS) with Azure Application Gateway or service mesh
- DAzure Key Vault for secret management
Show answer & explanationAnswer & explanation
Correct answer: C. Mutual TLS (mTLS) with Azure Application Gateway or service mesh
Mutual TLS (mTLS) provides both encryption in transit and mutual authentication, where both the client and server (in this case, microservices) verify each other's identities using certificates. This directly addresses the requirement for encrypted communication and identity verification between services.
Why the other options are wrong
- A. Azure Active Directory provides identity and access management, which is crucial for service principals, but mTLS specifically handles the cryptographic proof of identity and encryption during communication.
- B. Azure Front Door is a global, scalable entry point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications, often with WAF for inbound traffic, but not specifically for internal service-to-service mTLS.
- D. Azure Key Vault is for managing secrets and certificates, but it doesn't directly implement mTLS for service-to-service communication.
Mutual TLS (mTLS)
A security protocol where both the client and server authenticate each other using digital certificates as part of the TLS handshake. It ensures encrypted and mutually authenticated communication.
- Provides encryption in transit.
- Ensures mutual authentication (client verifies server, server verifies client).
- Often used in zero-trust architectures and microservices communication.
Memory trick: Microservices need to 'Talk Securely and Know Each Other' with mTLS.