Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You deployed an AKS cluster using Azure CNI without any extra parameters. Developers applied a Kubernetes NetworkPolicy YAML to restrict namespace-to-namespace traffic, but pods can still communicate freely. You must enforce the policy while continuing to use Azure CNI. What should you do?

  • Recreate the cluster and specify the --network-policy azure parameter during deployment.

  • Convert the cluster to a private cluster and disable the public API server endpoint.

  • Attach a network security group to the node subnet that blocks inter-pod traffic.

  • Create a PodSecurityPolicy that denies cross-namespace communication.

Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot