Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium

A development team is deploying a new containerized application to Azure Kubernetes Service (AKS). The application consists of a web frontend, an API backend, and a database service, each running in separate pods. To enhance security, they need to restrict communication between these pods based on their roles, ensuring that only the web frontend can communicate with the API backend, and only the API backend can communicate with the database service. Which Kubernetes resource should be implemented?

  1. AKubernetes Ingress Controller.
  2. BService Mesh like Istio.
  3. CAzure Network Security Groups (NSGs).
  4. DKubernetes Network Policies.
Show answer & explanation

Correct answer: D. Kubernetes Network Policies.

Kubernetes Network Policies allow you to define rules for how pods communicate with each other and with other network endpoints. They can restrict ingress and egress traffic based on labels, namespaces, and IP ranges, making them ideal for securing communication between specific pods within an AKS cluster based on their roles.

Why the other options are wrong

  • A. A Kubernetes Ingress Controller is used to manage external access to services within the cluster, typically HTTP/S, not for restricting internal pod-to-pod communication.
  • B. A Service Mesh like Istio can provide advanced traffic management and security features, including network policies, but Kubernetes Network Policies are the native, simpler solution for basic pod-to-pod communication restrictions as described.
  • C. Azure Network Security Groups (NSGs) operate at the virtual network subnet level and cannot provide the granular pod-level isolation required within an AKS cluster.

Kubernetes Network Policies

A Kubernetes resource that defines rules for controlling network traffic flow between pods, namespaces, and external endpoints within an AKS cluster, enabling granular isolation and security.

  • Operates at Layer 3/4 of the OSI model.
  • Defines ingress and egress rules for pods.
  • Based on pod labels and namespaces for targeting.
  • Requires a network plugin that supports NetworkPolicy (e.g., Azure CNI, Calico).

Memory trick: Use policy rules to control who talks to whom inside your Kubernetes cluster.

More Secure data and applications questions