Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionHard

A company is using Azure Container Instances (ACI) to run several short-lived, batch processing jobs. These containers handle sensitive data and require isolation from other containers and the underlying host operating system. The security team wants to ensure that the containers are running in a highly isolated environment, preventing any potential side-channel attacks or compromise from other workloads on the same host. Which ACI feature provides the strongest isolation for these containers?

  1. AVirtual Network (VNet) integration
  2. BHyper-V isolation for Linux containers
  3. CManaged identity for Azure resources
  4. DAzure Policy for container images
Show answer & explanation

Correct answer: B. Hyper-V isolation for Linux containers

Hyper-V isolation provides the strongest level of isolation for containers by running each container within a highly optimized virtual machine. This ensures a dedicated kernel and strong security boundaries, preventing side-channel attacks and providing a more secure environment compared to process isolation, which is the default for most Linux containers.

Why the other options are wrong

  • A. VNet integration secures network traffic but doesn't provide host-level isolation from other containers or the underlying OS.
  • C. Managed identities provide secure access to Azure resources but do not contribute to container runtime isolation.
  • D. Azure Policy for container images enforces standards on which images can be deployed, but it doesn't provide runtime isolation for the containers themselves.

Hyper-V Isolation for Containers

A container isolation mode where containers run inside highly optimized virtual machines, providing strong hardware-based isolation from the host and other containers.

  • Offers strongest isolation for containers.
  • Each container gets its own lightweight VM.
  • Protects against host kernel exploits and side-channel attacks.

Memory trick: Hyper-V isolation puts each container in its own secure bubble.

More Implement platform protection questions