Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionHard
A company is using Azure Container Instances (ACI) to run several short-lived, batch processing jobs. These jobs handle highly sensitive data and require the strongest possible isolation from other containers running on the same underlying host, even from other containers within the same ACI resource group. Which isolation mode should be selected for these ACI containers to meet the stringent security requirement?
- AKernel-level isolation
- BHyper-V isolation
- CProcess-level isolation
- DShared kernel isolation
Show answer & explanationAnswer & explanation
Correct answer: B. Hyper-V isolation
Hyper-V isolation provides the strongest level of isolation for containers, where each container runs in its own lightweight virtual machine. This ensures complete kernel isolation from the host and other containers, making it suitable for highly sensitive workloads requiring maximum security.
Why the other options are wrong
- A. Kernel-level isolation is a general term; Hyper-V isolation is the specific implementation for strong kernel isolation in Windows containers on Azure.
- C. Process-level isolation (used by Linux containers) offers less isolation, sharing the host kernel.
- D. Shared kernel isolation is typical for Linux containers and provides the least isolation, as they share the host OS kernel.
Hyper-V Isolation for ACI
Hyper-V isolation for Azure Container Instances (ACI) provides the strongest level of isolation for Windows containers by running each container in a dedicated, lightweight Hyper-V virtual machine.
- Offers full kernel isolation from the host and other containers.
- Suitable for multi-tenant environments and sensitive workloads.
- Ensures no shared kernel vulnerabilities with other containers.
- Primarily used for Windows containers on ACI.
Memory trick: Hyper-V: Each container gets its own fortified mini-VM.