Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataHard

A global retail company is deploying a new e-commerce platform on Azure Kubernetes Service (AKS). The application processes payment card industry (PCI) data and requires a high level of isolation and security for its containerized workloads. Specifically, the company needs to ensure that containers are run in a highly isolated environment with a strong hardware-backed boundary, preventing any unauthorized access or compromise of the host kernel. Which AKS feature should the security architect recommend?

  1. AAzure Private Link for AKS
  2. BAzure Policy for AKS
  3. CAzure Kubernetes Service with Kata Containers
  4. DAzure Container Instances (ACI)
Show answer & explanation

Correct answer: C. Azure Kubernetes Service with Kata Containers

AKS with Kata Containers provides a strong isolation boundary for containerized workloads by running them within lightweight virtual machines (VMs), effectively isolating them from the host kernel and other containers, which is critical for highly sensitive data like PCI.

Why the other options are wrong

  • A. Azure Private Link for AKS secures network connectivity to the AKS control plane, not runtime container isolation.
  • B. Azure Policy for AKS enforces compliance and governance rules, but does not provide runtime isolation for containers.
  • D. Azure Container Instances (ACI) provides isolated containers but is not an AKS feature for enhancing isolation within an AKS cluster.

AKS with Kata Containers

An Azure Kubernetes Service feature that provides enhanced isolation for containerized workloads by running each container within a lightweight virtual machine (VM) with a dedicated kernel, using Kata Containers technology.

  • Provides strong hardware-backed container isolation.
  • Each container runs in its own lightweight VM.
  • Protects the host kernel from container compromise.
  • Suitable for highly sensitive workloads like PCI.

Memory trick: Kata Containers put your containers in their own little fortresses.

More Design security for applications and data questions