Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium

A startup is deploying a multi-tier application to Azure Kubernetes Service (AKS). The application consists of a front-end web service and a back-end API service, each running in separate namespaces. The security team requires that the front-end service can only communicate with the back-end service, and the back-end service cannot initiate outbound connections to the internet. Which Kubernetes security construct should be used to enforce these communication restrictions?

  1. AService Mesh (e.g., Istio)
  2. BAzure Firewall
  3. CNetwork Policies
  4. DIngress Controller
Show answer & explanation

Correct answer: C. Network Policies

Kubernetes Network Policies are the native Kubernetes resource designed to control network traffic flow between pods/namespaces within an AKS cluster. They can enforce both ingress (front-end to back-end) and egress (back-end to no internet) restrictions.

Why the other options are wrong

  • A. A Service Mesh provides advanced traffic management, observability, and security features, but Network Policies are the fundamental construct for enforcing communication restrictions at the network layer.
  • B. Azure Firewall is a cloud-native network security service that protects Azure Virtual Network resources, typically used for VNet-level or external network traffic filtering, not granular pod-to-pod within a cluster.
  • D. An Ingress Controller manages external access to services within the cluster, typically for HTTP/S routing, and does not control internal pod-to-pod or pod-to-external communication restrictions.

Kubernetes Network Policies

A Kubernetes resource that defines how pods are allowed to communicate with each other and with other network endpoints.

  • Operate at Layer 3/4 of the OSI model.
  • Enforce both ingress (inbound) and egress (outbound) rules.
  • Applied to pods based on labels and namespaces.

Memory trick: Network Policies: Your cluster's traffic cop for pods.

More Secure data and applications questions