Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You administer an existing Azure Kubernetes Service (AKS) cluster that uses the Azure CNI network plugin and hosts workloads for several teams. All pods run in the same virtual-network subnet. A new requirement states that pods in the "finance" namespace must accept traffic only from pods in the "billing" namespace; traffic from every other namespace must be blocked. Communication between cluster nodes must remain unchanged. What should you do to meet the requirement?

  • Associate a user-defined route table to the pod subnet and add a route that drops packets whose source IP range is not assigned to the billing namespace.

  • Deploy an Azure Firewall in the virtual network and create application rules that allow traffic only from billing namespace pod IP addresses to the finance namespace.

  • Move finance pods to a separate subnet and configure network security group rules to allow traffic solely from the billing namespace subnet.

  • Enable Azure network policy on the AKS cluster and apply a Kubernetes NetworkPolicy that allows ingress to finance pods only from the billing namespace and denies other traffic.

Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot