Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You have an Azure Kubernetes Service (AKS) cluster that was created with a system-assigned managed identity. The cluster is deployed in Subscription1, while an Azure Container Registry (ACR) named contosoacr is hosted in Subscription2. You must enable the cluster nodes to pull images from contosoacr without storing any registry credentials inside the cluster and by granting only the minimum required privileges. What should you do?
Assign the Virtual Machine Contributor role to the resource group that contains the AKS node pools.
Create a repository-scoped token in contosoacr and store it as an imagePullSecret in the cluster.
Enable the admin user on contosoacr and create a docker-registry secret in the cluster with the admin credentials.
Assign the AcrPull role to the AKS cluster's managed identity at the scope of contosoacr.
AKS nodes authenticate to an ACR by using the cluster's managed identity when that identity has the AcrPull built-in role on the registry. The role lets the nodes read (pull) images but not push or administer the registry, satisfying least-privilege requirements. Enabling the admin user or creating repository-scoped tokens would require storing credentials in Kubernetes secrets, and assigning Virtual Machine Contributor does not grant image-pull permissions to ACR.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the AcrPull role in Azure, and why is it used for AKS clusters?
Open an interactive chat with Bash
What is a system-assigned managed identity, and how does it help in this scenario?
Open an interactive chat with Bash
Why is enabling the admin user or using repository-scoped tokens not recommended in this case?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .