Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You administer an Azure Kubernetes Service (AKS) cluster that hosts production workloads. Regulatory requirements state that any attempt to "exec" into a running container must be detected at runtime and trigger an alert almost immediately. The solution must use only built-in Azure capabilities and must not require you to manually deploy or maintain additional DaemonSets. Which service should you enable to meet these requirements?
Enable Azure Monitor Container insights for the Log Analytics workspace linked to the cluster.
Enable the Azure Policy add-on for Kubernetes on the AKS cluster.
Enable Microsoft Defender for Containers for the subscription that contains the AKS cluster.
Configure diagnostic settings on the AKS cluster to forward Kubernetes audit logs to a Log Analytics workspace.
Microsoft Defender for Containers provides built-in Kubernetes runtime threat detection for AKS. When the plan is enabled at the subscription (or resource) level in Microsoft Defender for Cloud, the necessary sensor is deployed automatically to each node as an extension, so no manual DaemonSet management is required. Defender for Containers generates near real-time security alerts for actions such as attempts to exec into a container.
Container insights focuses on performance and health monitoring, not runtime threat detection. The Azure Policy add-on prevents non-compliant deployments at admission time but does not monitor runtime actions. Streaming audit logs to Log Analytics can record events but does not automatically analyze them or raise security alerts in near real time.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Microsoft Defender for Containers?
Open an interactive chat with Bash
Why doesn’t Azure Monitor Container insights meet the requirement?
Open an interactive chat with Bash
How does Microsoft Defender for Containers compare to Kubernetes audit logs?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .