AZ-500 exam dumps

AZ-500 practice question 126 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 126

Single answer

Your organization is running a mission-critical application on Azure Kubernetes Service (AKS). You need to ensure that only images from a trusted container registry are deployed, containers do not run with unnecessary privileges, and all pod-level metrics and logs are captured for analysis. Which approach best meets these security and monitoring requirements?

  1. A

    A. Assign Azure RBAC roles to limit access to the cluster and rely on the standard Container Insights metrics.

  2. B

    B. Enable Azure Policy for AKS to restrict deployments to trusted registries, enforce no privileged containers, and configure Azure Monitor for containers.

  3. C

    C. Deploy a custom admission controller that automatically deletes pods from untrusted images and collect logs using only Kubernetes events.

  4. D

    D. Use Network Policies alone to prevent any external images from being pulled and rely on the default AKS cluster metrics.

Show answer and explanation

Correct answer: B

Explanation

Azure Policy for AKS provides built-in policies to restrict image sources and manage container privileges. Combined with Azure Monitor for containers (part of Container Insights), it offers a comprehensive approach to enforcing security standards and monitoring containerized workloads. Reference: https://learn.microsoft.com/azure/aks/use-azure-policy and https://learn.microsoft.com/azure/azure-monitor/containers/container-insights-overview.

  • A. Incorrect.

    A. While assigning Azure RBAC roles limits user access to the cluster, it does not prevent deployments from untrusted registries or guarantee containers do not run in privileged mode. Standard Container Insights provides basic metrics, but additional policy enforcement is required to meet the stated security requirements.

  • B. Correct.

    B. This option combines AKS integration with Azure Policy to enforce allowed container registries and block privileged containers, along with Azure Monitor for containers to collect in-depth metrics and logs for analysis. It addresses both security and monitoring needs in a unified way.

  • C. Incorrect.

    C. A custom admission controller can enforce certain restrictions, but maintaining a custom solution for untrusted images and relying only on Kubernetes events for logs is less comprehensive than Azure Monitor for containers, especially for large-scale or multi-cluster environments.

  • D. Incorrect.

    D. Network Policies can restrict traffic flow, but they do not control which container registry is used. Relying on default AKS metrics alone does not offer the full visibility needed for secure workloads.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam