Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionEasy
A financial institution uses Azure Kubernetes Service (AKS) to host sensitive microservices. They need to ensure that container images deployed to AKS are scanned for vulnerabilities before they are run. If critical vulnerabilities are found, the deployment should be blocked. Which Microsoft Defender for Cloud capability should be integrated with their AKS clusters to achieve this?
- AMicrosoft Defender for SQL
- BMicrosoft Defender for Containers
- CMicrosoft Defender for Servers
- DMicrosoft Defender for Cloud Apps
Show answer & explanationAnswer & explanation
Correct answer: B. Microsoft Defender for Containers
Microsoft Defender for Containers provides vulnerability scanning for images in Azure Container Registry and can enforce admission control to block deployments to AKS clusters if critical vulnerabilities are detected.
Why the other options are wrong
- A. Microsoft Defender for SQL provides protection for Azure SQL Database and SQL Servers on Azure VMs, not for containerized workloads.
- C. Microsoft Defender for Servers provides threat protection for virtual machines and physical servers, not specifically for container images or AKS deployments.
- D. Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that focuses on SaaS application security, not container image scanning.
Defender for Containers (AKS)
Microsoft Defender for Containers provides cloud-native security for containerized workloads, including vulnerability scanning of images in registries and runtime protection for Azure Kubernetes Service (AKS) clusters, with capabilities like admission control.
- Scans container images for vulnerabilities.
- Provides runtime protection for AKS clusters.
- Can block deployments with admission control.
- Integrates with Azure Container Registry and AKS.
Memory trick: Containers Need Vigilant Defense.