Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsEasy
A development team is deploying a new containerized application to Azure Kubernetes Service (AKS). The application consists of several microservices, and each microservice needs to communicate only with specific other microservices and the database. The security team wants to enforce these communication restrictions at the network layer within the AKS cluster. Which AKS security feature should be used?
- AKubernetes Network Policies
- BAzure Private Link
- CNetwork Security Groups (NSGs)
- DAzure Firewall
Show answer & explanationAnswer & explanation
Correct answer: A. Kubernetes Network Policies
Kubernetes Network Policies allow you to define rules for how pods communicate with each other and other network endpoints, which is precisely what's needed to restrict microservice communication within an AKS cluster.
Why the other options are wrong
- B. Azure Private Link provides private connectivity to Azure services but doesn't control inter-pod communication within an AKS cluster.
- C. NSGs operate at the subnet level within the VNet and cannot provide granular control over communication between individual pods within an AKS cluster.
- D. Azure Firewall operates at the VNet level for outbound and inbound traffic to/from the cluster, not for inter-pod communication within the cluster.
Kubernetes Network Policies
A Kubernetes resource that specifies how groups of pods are allowed to communicate with each other and with other network endpoints, providing network segmentation and isolation within a Kubernetes cluster.
- Enforces communication rules between pods.
- Operates at Layer 3/4 of the OSI model.
- Applied to pods based on labels.
Memory trick: Network Policies: the traffic cop for pods.