Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionEasy
A development team is deploying a new microservices application using Azure Kubernetes Service (AKS). They need to ensure that traffic between different microservices within the AKS cluster is restricted based on specific rules, allowing only authorized communication paths. Which Kubernetes resource should they use to define these communication restrictions?
- AService Mesh
- BNetwork Policy
- CIngress Controller
- DLoad Balancer
Show answer & explanationAnswer & explanation
Correct answer: B. Network Policy
Kubernetes Network Policies allow you to specify how groups of pods are allowed to communicate with each other and with other network endpoints. This is crucial for microservices architectures to enforce granular communication control.
Why the other options are wrong
- A. A Service Mesh (like Istio) provides advanced traffic management, observability, and security features, but Network Policies are the native Kubernetes resource for basic communication restrictions.
- C. Ingress Controllers manage external access to services within the cluster, not internal pod-to-pod communication.
- D. Load Balancers distribute incoming network traffic across multiple pods for a service, not to restrict communication between services.
Kubernetes Network Policies
Kubernetes Network Policies are specifications that define how groups of pods are allowed to communicate with each other and with other network endpoints.
- Enforce traffic filtering at the IP address or port level.
- Apply to ingress (incoming) and egress (outgoing) traffic.
- Are namespace-scoped resources.
- Require a network plugin that supports NetworkPolicy.
Memory trick: Network Policy: The bouncer for your microservices' internal club.