AZ-500 exam dumps

AZ-500 practice question 125 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 125

Select 2

You manage a microservices solution running on Azure Kubernetes Service (AKS) and store container images in Azure Container Registry (ACR). The security team requires automatic vulnerability scanning of container images before deployment and real-time threat detection for suspicious activity at runtime. Which two configurations should you implement to meet these requirements?

  1. A

    Enable Microsoft Defender for Containers in Microsoft Defender for Cloud

  2. B

    Apply an Azure Policy for AKS that restricts deployments to only trusted, scanned images

  3. C

    Enable Container Insights in Azure Monitor to automatically block images with vulnerabilities

  4. D

    Configure a custom initiative in Azure Policy to quarantine any containers flagged as suspicious at runtime

Show answer and explanation

Correct answers: A, B

Explanation

To secure and monitor AKS, Microsoft Defender for Containers (within Microsoft Defender for Cloud) offers automated vulnerability scanning for images in Azure Container Registry and provides advanced threat detection for AKS at runtime. Azure Policy enforces security rules, such as restricting deployments to scanned or trusted images. Combining these two features helps ensure a secure container deployment pipeline and continuous monitoring. For more details, see Microsoft’s documentation: https://learn.microsoft.com/azure/defender-for-cloud/defender-for-containers-introduction.

  • A. Correct.

    Correct. Enabling Microsoft Defender for Containers provides both image scanning in Azure Container Registry (as part of its vulnerability assessment) and advanced runtime threat detection features for AKS clusters. It is a key service for securing and monitoring containerized workloads.

  • B. Correct.

    Correct. By applying an Azure Policy for AKS, you can enforce which container images can be deployed (for example, those that have been scanned and meet certain compliance criteria). This helps prevent unscanned or vulnerable images from running in the cluster.

  • C. Incorrect.

    Incorrect. Container Insights in Azure Monitor collects logs and performance metrics, but it does not automatically block images with vulnerabilities. It is useful for monitoring, but it does not provide vulnerability scanning or preventive blocking features.

  • D. Incorrect.

    Incorrect. Azure Policy does not provide a built-in runtime quarantine mechanism for suspicious containers. While Azure Policy can enforce configurations at deployment time, the ability to detect and quarantine containers at runtime falls under Microsoft Defender for Cloud’s threat protection features.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam