Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityHard

A company is developing a new microservices application using Azure Kubernetes Service (AKS). The application consists of several microservices that communicate with each other. The security team mandates a zero-trust network policy, meaning that no microservice should implicitly trust another, and all inter-service communication must be authenticated and authorized. Which security pattern should be implemented to enforce this zero-trust communication within the AKS cluster?

  1. AService Mesh (e.g., Istio or Linkerd)
  2. BAzure Private Link
  3. CKubernetes Network Policies
  4. DNetwork Security Groups (NSG)
Show answer & explanation

Correct answer: A. Service Mesh (e.g., Istio or Linkerd)

A Service Mesh (like Istio or Linkerd) is specifically designed to handle inter-service communication, including traffic management, observability, and security. For zero-trust, a service mesh provides features like mutual TLS (mTLS) for authenticating and encrypting all service-to-service communication, and fine-grained authorization policies based on service identity, enforcing the 'never trust, always verify' principle.

Why the other options are wrong

  • B. Azure Private Link provides private connectivity to Azure PaaS services (e.g., Storage, SQL Database) from a VNet. It is not designed to secure inter-service communication within an AKS cluster.
  • C. Kubernetes Network Policies enforce Layer 3/4 packet filtering between pods based on labels. While useful for segmentation, they do not provide identity-based authentication (mTLS) or fine-grained authorization policies at the application layer necessary for a full zero-trust model.
  • D. Network Security Groups (NSGs) operate at Layer 4 (IP/port) and provide basic network filtering between subnets or VMs. They are not granular enough for per-service authentication and authorization within a Kubernetes cluster for zero-trust.

Service Mesh for Zero-Trust

A dedicated infrastructure layer that handles inter-service communication within a microservices architecture, enabling features like mutual TLS for zero-trust security.

  • Provides mutual TLS (mTLS) for authenticating and encrypting all service-to-service traffic.
  • Enforces fine-grained authorization policies based on service identity.
  • Offers traffic management, observability, and resiliency features.

Memory trick: Service Mesh: Every microservice gets its own security guard and ID check.

More Implement Azure security questions