Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You manage an existing AKS cluster that developers currently access with the client certificates generated at deployment. For an upcoming audit you must (1) require developers to sign in with their Azure AD identities, (2) administer authorization through Azure RBAC or Azure AD groups, and (3) avoid redeploying any running workloads. What should you do?
Configure basic authentication with static bearer tokens stored in Azure Key Vault.
Create Kubernetes service accounts mapped to individual Azure AD users by using Azure AD workload identities.
Enable managed Azure AD integration on the cluster and turn on Azure RBAC for Kubernetes.
Install the Open Service Mesh (OSM) add-on and require mutual TLS between all pods.
Enabling managed Azure AD integration adds Microsoft Entra (Azure AD) as an identity provider for the Kubernetes API, allowing kubectl users to authenticate with their Azure AD credentials. When you also enable Azure RBAC for Kubernetes, authorization decisions can be based on Azure AD group membership. These changes are applied at the control-plane level and do not require redeploying existing workloads. Basic authentication with static tokens is deprecated and insecure, Kubernetes service accounts address workload (non-human) identity, and the Open Service Mesh add-on only secures pod-to-pod traffic and does not affect API-server authentication.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is managed Azure AD integration for AKS?
Open an interactive chat with Bash
How does Azure RBAC for Kubernetes differ from Kubernetes RBAC?
Open an interactive chat with Bash
Why is basic authentication with static tokens insecure?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .