問題文
Two internal services exchange personal data. Adding mutual authentication and transport encryption to every internal call adds latency and operational work on certificates. A reviewer asks whether it is worth it for internal traffic. What is the sound position?
選択肢
- It is necessary only for traffic that crosses a data center boundary.
- It is justified and there is no cost, because certificates can be issued automatically, and a platform that renews them without human involvement leaves nothing extra to operate at all.
- It is not worth it for traffic that stays inside a segmented network, because the segment boundary already establishes which workloads can reach the service and adding cryptographic identity to each call duplicates that decision at a second layer while introducing a failure mode that did not previously exist, namely the expiry of a certificate taking down a working path.
- It is worth it because a position on the internal network is not evidence of trustworthiness; the cost is certificate lifecycle work, which has to be automated to be sustainable.