Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You have an Azure Kubernetes Service (AKS) cluster that was created with a system-assigned managed identity. The cluster is deployed in Subscription1, while an Azure Container Registry (ACR) named contosoacr is hosted in Subscription2. You must enable the cluster nodes to pull images from contosoacr without storing any registry credentials inside the cluster and by granting only the minimum required privileges. What should you do?

  • Assign the Virtual Machine Contributor role to the resource group that contains the AKS node pools.

  • Create a repository-scoped token in contosoacr and store it as an imagePullSecret in the cluster.

  • Enable the admin user on contosoacr and create a docker-registry secret in the cluster with the admin credentials.

  • Assign the AcrPull role to the AKS cluster's managed identity at the scope of contosoacr.

Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot