Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsHard
A large enterprise uses Azure Kubernetes Service (AKS) to host mission-critical applications. To comply with corporate security policies, all outbound traffic from the AKS cluster must be inspected and filtered by a centralized firewall appliance. This includes traffic to both public internet endpoints and other Azure services. Which Azure networking service should be implemented to meet this requirement?
- AAzure Network Security Groups (NSGs) configured on the AKS subnets.
- BAzure Firewall integrated with AKS.
- CAzure Application Gateway with Web Application Firewall (WAF).
- DKubernetes Network Policies for egress control.
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Firewall integrated with AKS.
Azure Firewall is a cloud-native, intelligent network firewall security service that provides threat protection for your cloud workloads. It can be integrated with AKS to filter all outbound traffic from the cluster, including traffic to the public internet and other Azure services, ensuring centralized inspection and compliance with corporate security policies.
Why the other options are wrong
- A. NSGs operate at the subnet level and provide basic 5-tuple filtering. They do not offer advanced threat inspection, FQDN filtering for all outbound traffic, or centralized management capabilities like Azure Firewall.
- C. Azure Application Gateway with WAF is primarily an L7 load balancer and WAF for *inbound* web traffic, not a centralized firewall for *all outbound* traffic from an AKS cluster.
- D. Kubernetes Network Policies control pod-to-pod and pod-to-external communication *within* the cluster or to specific IP ranges, but they do not provide a centralized, enterprise-grade firewall for *all* outbound traffic with advanced inspection capabilities as a dedicated firewall service does.
Azure Firewall for AKS Outbound
Integrating Azure Firewall with an Azure Kubernetes Service (AKS) cluster to centrally inspect and filter all outbound network traffic from the cluster, ensuring compliance and enhanced security.
- Provides centralized egress traffic filtering for AKS.
- Supports FQDN-based filtering, network rules, and application rules.
- Offers advanced threat protection features.
- Helps meet regulatory compliance for traffic inspection.
Memory trick: Make sure all traffic leaving your AKS cluster passes through a strict security checkpoint.