mediumMultiple Choice
SC-100 Practice Question: Designing a microservices architecture on Azure…
A company is designing a microservices architecture on Azure Kubernetes Service (AKS). They need to secure communication between services using mutual TLS (mTLS). Which solution should they implement?
⚠ Common exam trap
Test-takers frequently confuse ingress/egress security appliances (like Application Gateway or API Management) with internal service-to-service security, assuming a gateway can handle mTLS for east-west traffic when it is designed only for north-south traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Istio service mesh
Istio service mesh is the correct solution because it provides a dedicated infrastructure layer for managing service-to-service communication, including automatic mutual TLS (mTLS) between microservices. Istio injects Envoy sidecar proxies into each pod, which handle encryption, authentication, and authorization without requiring application code changes. This enables zero-trust network security within the AKS cluster.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Application Gateway
Why it's wrong here
Azure Application Gateway is a Layer-7 HTTP load balancer that handles north-south traffic by terminating client TLS and routing requests based on URL/path. It cannot be inserted transparently into service-to-service communication, so it lacks the sidecar-based identity and per-hop mTLS needed for inter-microservice security. It is designed for inbound HTTP load balancing, not for enforcing mutual TLS between internal microservices.
- ✗
Azure Firewall
Why it's wrong here
Azure Firewall is a stateful network security service that filters traffic at the network and FQDN level across Azure virtual networks and subnets. It does not participate in the application data path between microservices, cannot issue or verify workload certificates, and provides no service identity mechanism. Therefore, it cannot enforce mutual TLS between individual services; it is for network traffic filtering, not for service-to-service encryption or authentication.
- ✗
Azure API Management
Why it's wrong here
Azure API Management acts as an external API gateway, applying policies, authentication, quotas, and transformations to requests at the API boundary. It is not an internal service mesh because it does not inject proxies into each workload or intercept arbitrary east-west traffic; its client-certificate support only handles direct calls to the APIM endpoint, not service-to-service calls inside the cluster. While it is an API gateway, it is not a solution for internal service mesh mTLS.
- ✓
Istio service mesh
Why this is correct
Istio service mesh runs Envoy sidecar proxies next to each microservice, giving it the ability to issue SPIFFE-based identities and automatically encrypt and authenticate all service-to-service traffic with mutual TLS. It also provides authorization policies and traffic management, making it the correct solution for internal microservice mTLS on Azure Kubernetes Service or virtual machines. This directly addresses the need for workload-level identity and encryption between microservices.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.