Microsoft Azure Security Engineer Associate AZ-500 Practice Question

Your organization operates several Azure Kubernetes Service (AKS) clusters. You must prevent developers from deploying containers that request host networking or run privileged containers. Violations must be denied at admission time and surfaced as policy compliance results in Microsoft Defender for Cloud. Which feature should you enable on each cluster?

  • Azure Monitor Container Insights

  • Only enable Microsoft Defender for Cloud at the subscription level

  • Kubernetes Pod Security Admission enforcement

  • Azure Policy add-on for Kubernetes in the AKS cluster

Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot