Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionHard

A development team is deploying several containerized microservices to Azure Container Instances (ACI). These microservices process highly sensitive data and require the strongest possible isolation from other containers and the underlying host operating system. Standard shared-kernel isolation is deemed insufficient. Which specific isolation mode for ACI should the team choose to meet this stringent security requirement?

  1. AProcess-based isolation
  2. BHyper-V isolation
  3. CNamespace isolation
  4. DShared-kernel isolation
Show answer & explanation

Correct answer: B. Hyper-V isolation

Hyper-V isolation provides the strongest level of isolation for containers in ACI. It runs each container in a highly optimized virtual machine, providing kernel-level isolation from other containers and the host operating system, which is critical for highly sensitive workloads requiring maximum security.

Why the other options are wrong

  • A. Process-based isolation is typically used for Linux containers and shares the host kernel, offering less isolation than Hyper-V.
  • C. Namespace isolation is a feature of Linux containers that isolates resources but still shares the host kernel, offering weaker isolation than Hyper-V.
  • D. Shared-kernel isolation is the default for Linux containers and is explicitly stated as insufficient for the given requirements.

Azure Container Instances Hyper-V Isolation

Hyper-V isolation for Azure Container Instances runs each container within its own dedicated, lightweight Hyper-V virtual machine, providing strong kernel-level isolation from other containers and the host.

  • Offers the strongest isolation for Windows containers (and some Linux).
  • Each container group runs in its own dedicated Hyper-V VM.
  • Prevents kernel-level exploits from affecting other containers or the host.
  • Important for multi-tenant environments with sensitive workloads.

Memory trick: For ultimate container security, 'Hyper-V' creates a private VM fortress.

More Implement platform protection questions