2V0-71.23 Question 277
Select 2Your organization is using VMware Tanzu Service Mesh Advanced to manage microservices communication across multiple Kubernetes clusters in different regions. A critical business requirement is to ensure end-to-end encryption of all service-to-service traffic and to verify that only authorized services can communicate with each other. Additionally, the operations team must have visibility into traffic flows for troubleshooting. Which features of Tanzu Service Mesh Advanced should you configure to meet these requirements?
- A
mTLS (Mutual Transport Layer Security)
- B
Global Namespace
- C
Access Control Policies
- D
Service Level Objectives (SLOs)
- E
Traffic Mirroring
Show answer and explanation
Correct answers: A, C
Explanation
To meet the requirements of end-to-end encryption and authorized service communication, you need to configure mTLS for encryption and Access Control Policies for enforcing communication rules. While other features like Global Namespace and Traffic Mirroring can be helpful in other contexts, they do not directly address the specified requirements.
- A. Correct.
mTLS ensures end-to-end encryption and mutual authentication between services, meeting the requirement for secure communication.
- B. Incorrect.
While Global Namespace simplifies service discovery and communication across multiple Kubernetes clusters, it does not directly address encryption or access control.
- C. Correct.
Access Control Policies restrict which services are allowed to communicate with each other, addressing the requirement for authorized communication.
- D. Incorrect.
Service Level Objectives (SLOs) are used to monitor and measure application performance but do not address encryption or access control.
- E. Incorrect.
Traffic Mirroring is useful for debugging or testing in production-like scenarios but does not provide encryption or access control.