Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityHard

A company is developing a new microservices application using Azure Kubernetes Service (AKS). Each microservice needs to securely call other internal microservices within the AKS cluster, and also external Azure services like Azure Key Vault and Azure Cosmos DB. The security team insists on using a zero-trust model, meaning every service call must be explicitly authenticated and authorized. Which solution provides the most robust and scalable way to enforce identity-based access control between microservices within AKS and to external Azure services?

  1. AUse static API keys for each microservice and distribute them as Kubernetes Secrets.
  2. BImplement mutual TLS (mTLS) with a service mesh (e.g., Istio or Linkerd) for internal communication, and Workload Identity for external Azure services.
  3. CEmbed client certificates directly into each microservice's container image for mTLS.
  4. DRely on Network Security Groups (NSGs) and Kubernetes Network Policies to restrict traffic flow.
Show answer & explanation

Correct answer: B. Implement mutual TLS (mTLS) with a service mesh (e.g., Istio or Linkerd) for internal communication, and Workload Identity for external Azure services.

A service mesh (like Istio or Linkerd) with mTLS provides robust identity-based authentication and authorization for *internal* microservice-to-microservice communication within AKS, aligning with zero-trust principles. For *external* Azure services, Azure AD Workload Identity (formerly Azure AD Pod Identity) provides a secure, secretless way for pods to authenticate using Azure AD identities, eliminating the need for managing credentials.

Why the other options are wrong

  • A. Static API keys are prone to leakage, difficult to rotate, and do not align with a zero-trust model for identity-based authentication.
  • C. Embedding certificates in container images makes certificate rotation and management cumbersome and introduces security risks if images are compromised. A service mesh abstracts this.
  • D. NSGs and Network Policies control *network access* (who can talk to whom by IP/port), but they do not provide *identity-based authentication and authorization* for the service calls themselves, which is a core tenet of zero-trust.

AKS Zero-Trust Microservice Security

Implementing identity-based authentication and authorization for microservices in AKS, both for inter-service communication within the cluster and for accessing external Azure services.

  • Service Mesh with mTLS for internal communication (service identity).
  • Azure AD Workload Identity for external Azure service access (pod identity).
  • Eliminates static credentials and provides fine-grained authorization.
  • Core components of a zero-trust architecture in AKS.

Memory trick: Service Mesh for inside, Workload Identity for outside, that's Zero Trust.

More Implement Azure security questions