A company is using Azure Kubernetes Service (AKS) for a production workload. They require a solution to analyze container images for known vulnerabilities before deployment, enforce security policies at runtime, and monitor for suspicious activities within the cluster. The solution must integrate seamlessly with AKS and provide a unified security management experience. Which Azure security service should be implemented?
- AAzure Policy for Kubernetes
- BAzure Monitor for Containers
- CAzure Security Center (Defender for Cloud) with Defender for Containers
- DAzure Container Registry (ACR) built-in vulnerability scanning
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Security Center (Defender for Cloud) with Defender for Containers
Microsoft Defender for Cloud, specifically with its Defender for Containers plan, provides a comprehensive solution for AKS security. It offers vulnerability assessment for container images, runtime threat protection for nodes and clusters, and integration with admission controllers for policy enforcement during deployment. This fulfills all requirements for image scanning, runtime protection, and unified security management.
Why the other options are wrong
- A. Azure Policy for Kubernetes enforces policies on cluster resources but does not provide vulnerability scanning of images or advanced runtime threat detection.
- B. Azure Monitor for Containers collects and analyzes performance logs and metrics but does not perform vulnerability scanning, policy enforcement, or advanced threat detection.
- D. Azure Container Registry (ACR) has basic vulnerability scanning (via Defender for Cloud integration), but it's limited to images *in the registry* and doesn't provide runtime protection or policy enforcement within AKS.
Microsoft Defender for Containers
A cloud-native security solution within Microsoft Defender for Cloud that provides comprehensive threat protection for containerized environments, including vulnerability management, runtime protection, and policy enforcement.
- Scans container images for vulnerabilities.
- Provides runtime threat detection for AKS clusters and nodes.
- Integrates with Kubernetes admission control for policy enforcement.
Memory trick: Defender for Containers defends your entire container lifecycle, from image to runtime.