Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium

An e-commerce company uses Azure Kubernetes Service (AKS) for a production workload. They require a security solution that can continuously monitor vulnerabilities in container images, detect runtime threats in running pods, and enforce security best practices across their AKS clusters. Which Azure security service should they implement?

  1. AAzure Policy with custom definitions for Kubernetes.
  2. BAzure Network Security Groups (NSGs) for pod isolation.
  3. CMicrosoft Defender for Cloud (Containers plan).
  4. DAzure Sentinel for Security Information and Event Management (SIEM).
Show answer & explanation

Correct answer: C. Microsoft Defender for Cloud (Containers plan).

Microsoft Defender for Cloud, specifically its Containers plan, is designed to provide comprehensive security for AKS clusters. It offers capabilities for continuous vulnerability assessment of container images (registry and runtime), host hardening, runtime threat detection for pods and nodes, and enforcement of security best practices, directly addressing all stated requirements.

Why the other options are wrong

  • A. Azure Policy can enforce compliance and best practices at the resource level, but it does not provide the active vulnerability scanning or runtime threat detection capabilities specific to containers and Kubernetes that are required.
  • B. NSGs are for network traffic filtering at the VM/subnet level, not for container image vulnerability scanning, runtime threat detection within pods, or security best practices enforcement at the cluster level.
  • D. Azure Sentinel is a SIEM solution for collecting and analyzing security data across various sources, but it doesn't natively provide image vulnerability scanning or runtime threat detection for containers itself; it consumes data from services like Defender for Cloud.

Microsoft Defender for Cloud (Containers)

A cloud-native security solution that provides comprehensive threat protection and security posture management for containerized workloads, including vulnerability assessment, runtime threat detection, and security recommendations for Azure Kubernetes Service (AKS).

  • Scans container images for vulnerabilities in Azure Container Registry and during runtime.
  • Detects runtime threats to pods, nodes, and clusters.
  • Provides security recommendations based on best practices.
  • Integrates with Azure Policy for compliance enforcement.

Memory trick: Defend your containers from build to runtime with a centralized cloud guardian.

More Secure data and applications questions