Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsEasy
A development team is deploying a new containerized application to Azure Kubernetes Service (AKS). The application processes financial transactions and requires strict isolation between different microservices within the same cluster. Specifically, the payment processing microservice should only be able to communicate with the database microservice, and no other microservices or external endpoints. Which Kubernetes resource should be used to enforce these communication restrictions?
- ANetwork Policy
- BService Mesh
- CIngress Controller
- DAzure Firewall
Show answer & explanationAnswer & explanation
Correct answer: A. Network Policy
Kubernetes Network Policies are the native and most direct way to define and enforce communication rules between pods and namespaces within an AKS cluster, perfectly matching the requirement for strict isolation and specific communication paths between microservices.
Why the other options are wrong
- B. A Service Mesh (e.g., Istio) provides advanced traffic management, observability, and security features at the application layer, but Network Policies are the foundational resource for controlling traffic at the network layer within Kubernetes.
- C. An Ingress Controller manages external access to services within the cluster, typically for HTTP/S routing, not internal pod-to-pod communication restrictions.
- D. Azure Firewall is a network security service used for filtering traffic at the virtual network level, not for granular pod-to-pod communication within an AKS cluster.
Kubernetes Network Policy
A Kubernetes resource that specifies how groups of pods are allowed to communicate with each other and with external network endpoints.
- Enforces both inbound (ingress) and outbound (egress) rules.
- Applied using label selectors to target specific pods.
- Provides granular network segmentation within a cluster.
Memory trick: Network Policy: Your cluster's traffic cop for pod conversations.