Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsHard
A large enterprise uses Azure Kubernetes Service (AKS) to host mission-critical applications. The security team requires that all outbound traffic from the AKS cluster to the internet is filtered and audited according to corporate security policies. They also need to ensure that specific FQDNs are allowed or denied. Which Azure networking service should be deployed and configured for this purpose?
- ANetwork Security Groups (NSGs)
- BAzure Firewall
- CAzure Application Gateway
- DAzure Front Door
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Firewall
Azure Firewall provides centralized network security for all outbound traffic from AKS, offering FQDN filtering capabilities, threat intelligence, and logging for auditing, which aligns with the enterprise's requirements.
Why the other options are wrong
- A. NSGs can filter traffic based on IP addresses and ports but lack FQDN filtering and advanced threat intelligence for outbound traffic from an AKS cluster.
- C. Azure Application Gateway is primarily a web traffic load balancer and WAF for inbound HTTP/S traffic, not for filtering outbound internet traffic from AKS.
- D. Azure Front Door is a global, scalable entry point using the Microsoft global edge network to create fast, secure, and widely scalable web applications, primarily for inbound traffic and CDN capabilities, not outbound filtering from AKS.
Azure Firewall for AKS Outbound Traffic
Azure Firewall is a cloud-native, intelligent network firewall security service that provides highly available and scalable network security for all your Azure Virtual Network resources, including outbound filtering for Azure Kubernetes Service (AKS) clusters.
- Provides FQDN-based filtering for outbound traffic.
- Offers network and application rule collections.
- Integrates with Azure Monitor for auditing and logging.
Memory trick: Azure Firewall: AKS's strict internet bouncer.