Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You deployed an AKS cluster using Azure CNI without any extra parameters. Developers applied a Kubernetes NetworkPolicy YAML to restrict namespace-to-namespace traffic, but pods can still communicate freely. You must enforce the policy while continuing to use Azure CNI. What should you do?
Recreate the cluster and specify the --network-policy azure parameter during deployment.
Convert the cluster to a private cluster and disable the public API server endpoint.
Attach a network security group to the node subnet that blocks inter-pod traffic.
Create a PodSecurityPolicy that denies cross-namespace communication.
Kubernetes NetworkPolicy objects are only enforced in AKS when the cluster is created with the network policy add-in enabled. For Azure CNI this is done by passing the parameter --network-policy azure (or --network-policy calico). Network policy cannot be enabled after deployment, so the cluster must be recreated. Network security groups operate at the subnet level and do not understand pod labels, PodSecurityPolicy does not control network flow, and making the cluster private does not affect intra-cluster traffic.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure CNI in AKS?
Open an interactive chat with Bash
What is a Kubernetes NetworkPolicy and how does it work?
Open an interactive chat with Bash
Why can’t a cluster’s network policy be enabled after deployment in AKS?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .