Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium
An e-commerce company uses Azure Kubernetes Service (AKS) to host its containerized microservices. They want to ensure that all container images deployed to AKS are scanned for vulnerabilities before being allowed to run. If critical vulnerabilities are found, the deployment should be blocked automatically. Which Azure security service should be integrated with AKS to achieve this?
- AMicrosoft Defender for Cloud (Containers plan)
- BAzure Policy
- CAzure Security Center (Standard tier)
- DAzure Container Registry (ACR) with vulnerability scanning
Show answer & explanationAnswer & explanation
Correct answer: A. Microsoft Defender for Cloud (Containers plan)
Microsoft Defender for Cloud's Containers plan specifically offers vulnerability assessment for images in ACR and provides admission control for AKS, allowing it to block deployments with critical vulnerabilities.
Why the other options are wrong
- B. Azure Policy can enforce rules for AKS resource creation but doesn't inherently scan container images for vulnerabilities.
- C. Azure Security Center (now Microsoft Defender for Cloud) is the overarching service, but the specific 'Containers' plan is needed for this functionality.
- D. ACR with vulnerability scanning (provided by Defender for Cloud) scans images, but by itself, it doesn't automatically block AKS deployments.
Microsoft Defender for Cloud (Containers plan)
A security solution that provides cloud-native protection for containers, including vulnerability assessment for images in Azure Container Registry (ACR) and runtime threat protection for Azure Kubernetes Service (AKS) clusters.
- Scans container images for vulnerabilities.
- Provides admission control for AKS to block vulnerable deployments.
- Offers runtime protection for AKS nodes and clusters.
Memory trick: Defender guards the containers from registry to runtime.