Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureHard

A software-as-a-service (SaaS) provider is designing its Zero Trust architecture. They host multiple customer tenants within a shared Azure Kubernetes Service (AKS) cluster. A critical requirement is to ensure that while resources are shared, each customer's data and applications are strictly isolated from other tenants, with no possibility of cross-tenant data leakage or unauthorized access, even in the event of a compromise in an adjacent tenant. Which architectural approach is MOST effective for achieving this stringent isolation in a multi-tenant AKS environment?

  1. AUtilizing Kubernetes Network Policies to segment traffic within the cluster.
  2. BImplementing network security groups (NSGs) at the subnet level for the AKS cluster.
  3. CDeploying separate AKS clusters for each customer tenant.
  4. DEnforcing identity-based micro-segmentation using service mesh technologies.
Show answer & explanation

Correct answer: D. Enforcing identity-based micro-segmentation using service mesh technologies.

Identity-based micro-segmentation, often achieved with service mesh technologies, provides the most granular and robust isolation in a multi-tenant AKS cluster. It enforces policies at the workload (pod/service) level based on cryptographic identities, ensuring that even if a network segment is compromised, unauthorized communication between tenants is prevented, aligning with Zero Trust's 'Assume Breach' and 'Least Privilege' principles.

Why the other options are wrong

  • A. Kubernetes Network Policies provide pod-level network segmentation but are still primarily IP-based and do not inherently provide cryptographic identity-based isolation or advanced traffic management features of a service mesh.
  • B. NSGs operate at the network layer (Layer 3/4) and are too coarse-grained for strict isolation within a shared AKS cluster and do not provide identity-based enforcement.
  • C. Deploying separate AKS clusters for each tenant provides strong isolation but is often cost-prohibitive and operationally complex for a SaaS provider with many tenants. The question asks for an approach *within* a shared cluster.

Identity-Based Micro-segmentation (AKS Multi-tenant)

A security approach that enforces granular network access policies between individual workloads (e.g., pods) within a shared Kubernetes cluster based on cryptographic identities.

  • Enforces 'least privilege' at the workload level.
  • Uses cryptographic identities for authentication and authorization.
  • Prevents lateral movement and cross-tenant data leakage in shared environments.

Memory trick: Identity micro-segmentation: Each pod has its own secure ID.

More Design a Zero Trust strategy and architecture questions