🔥 40% Off Crucial Exams Memberships — This Week Only

6 hours, 6 minutes remaining!

Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You manage an Azure Kubernetes Service (AKS) cluster that uses the Azure CNI network plugin. Workloads from several teams run in separate namespaces. The security team requires that pods be isolated so that traffic between namespaces is blocked unless explicitly allowed. You need to enforce this requirement without modifying the cluster network plugin or the container images. What should you do?

  • Enable the Azure network policy add-on for the cluster and apply Kubernetes NetworkPolicy objects to each namespace.

  • Deploy Azure Firewall and route all pod egress traffic through it, adding deny rules for other namespaces.

  • Enable Microsoft Defender for Cloud for Kubernetes and configure the "Block cross-namespace communication" security policy.

  • Associate a network security group with each node subnet that blocks traffic between the pod address ranges.

Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot