Courseiva
mediumMultiple Choice

SC-100 Practice Question: Designing a microservices architecture on Azure…

A company is designing a microservices architecture on Azure Kubernetes Service (AKS). They need to secure communication between services using mutual TLS (mTLS). Which solution should they implement?

⚠ Common exam trap

Test-takers frequently confuse ingress/egress security appliances (like Application Gateway or API Management) with internal service-to-service security, assuming a gateway can handle mTLS for east-west traffic when it is designed only for north-south traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Istio service mesh

Istio service mesh is the correct solution because it provides a dedicated infrastructure layer for managing service-to-service communication, including automatic mutual TLS (mTLS) between microservices. Istio injects Envoy sidecar proxies into each pod, which handle encryption, authentication, and authorization without requiring application code changes. This enables zero-trust network security within the AKS cluster.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Application Gateway

    Why it's wrong here

    Azure Application Gateway is a Layer-7 HTTP load balancer that handles north-south traffic by terminating client TLS and routing requests based on URL/path. It cannot be inserted transparently into service-to-service communication, so it lacks the sidecar-based identity and per-hop mTLS needed for inter-microservice security. It is designed for inbound HTTP load balancing, not for enforcing mutual TLS between internal microservices.

  • ✗

    Azure Firewall

    Why it's wrong here

    Azure Firewall is a stateful network security service that filters traffic at the network and FQDN level across Azure virtual networks and subnets. It does not participate in the application data path between microservices, cannot issue or verify workload certificates, and provides no service identity mechanism. Therefore, it cannot enforce mutual TLS between individual services; it is for network traffic filtering, not for service-to-service encryption or authentication.

  • ✗

    Azure API Management

    Why it's wrong here

    Azure API Management acts as an external API gateway, applying policies, authentication, quotas, and transformations to requests at the API boundary. It is not an internal service mesh because it does not inject proxies into each workload or intercept arbitrary east-west traffic; its client-certificate support only handles direct calls to the APIM endpoint, not service-to-service calls inside the cluster. While it is an API gateway, it is not a solution for internal service mesh mTLS.

  • ✓

    Istio service mesh

    Why this is correct

    Istio service mesh runs Envoy sidecar proxies next to each microservice, giving it the ability to issue SPIFFE-based identities and automatically encrypt and authenticate all service-to-service traffic with mutual TLS. It also provides authorization policies and traffic management, making it the correct solution for internal microservice mTLS on Azure Kubernetes Service or virtual machines. This directly addresses the need for workload-level identity and encryption between microservices.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.